Problem Note 70625: The MI procedure contains a security vulnerability when a long character variable is specified in the ADJUSTOBS= option
Severity: High
Description: If UTF-8 encoding is used and a long character variable (greater than 255 bytes) is specified in the ADJUSTOBS= option in the MNAR statement, PROC MI might issue an overflow error.
To circumvent the problem, shorten the length of the variable to less than 255 bytes.
Potential Impact: The resulting overflow introduces a potential security risk.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS/STAT | z/OS | 15.2 | | 9.4 TS1M8 | |
Microsoft® Windows® for x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8 Enterprise 32-bit | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8 Enterprise x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8 Pro 32-bit | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8 Pro x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8.1 Enterprise 32-bit | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8.1 Enterprise x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8.1 Pro 32-bit | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 8.1 Pro x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 10 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows 11 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2008 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2008 R2 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2008 for x64 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2012 Datacenter | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2012 R2 Datacenter | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2012 R2 Std | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2012 Std | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2016 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2019 | 15.2 | | 9.4 TS1M8 | |
Microsoft Windows Server 2022 | 15.2 | | 9.4 TS1M8 | |
Windows 7 Enterprise 32 bit | 15.2 | | 9.4 TS1M8 | |
Windows 7 Enterprise x64 | 15.2 | | 9.4 TS1M8 | |
Windows 7 Home Premium 32 bit | 15.2 | | 9.4 TS1M8 | |
Windows 7 Home Premium x64 | 15.2 | | 9.4 TS1M8 | |
Windows 7 Professional 32 bit | 15.2 | | 9.4 TS1M8 | |
Windows 7 Professional x64 | 15.2 | | 9.4 TS1M8 | |
Windows 7 Ultimate 32 bit | 15.2 | | 9.4 TS1M8 | |
Windows 7 Ultimate x64 | 15.2 | | 9.4 TS1M8 | |
64-bit Enabled AIX | 15.2 | | 9.4 TS1M8 | |
64-bit Enabled Solaris | 15.2 | | 9.4 TS1M8 | |
HP-UX IPF | 15.2 | | 9.4 TS1M8 | |
Linux for x64 | 15.2 | | 9.4 TS1M8 | |
Solaris for x64 | 15.2 | | 9.4 TS1M8 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
An overflow error can occur if UTF-8 encoding is used and a very long character variable is specified in the ADJUSTOBS= option in PROC MI
Type: | Problem Note |
Priority: | high |
Topic: | Analytics ==> Missing Value Imputation SAS Reference ==> Procedures ==> MI
|
Date Modified: | 2024-02-09 11:31:35 |
Date Created: | 2024-01-25 15:03:30 |