SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70600: SAS/ACCESS® components in SAS® Viya® 3.5 contain a cURL library that are vulnerable to CVE-2023-38545 and CVE-2023-38546

DetailsHotfixAboutRate It

Severity: Critical

Description: SAS/ACCESS components in SAS Viya 3.5 contain a cURL library that are vulnerable to CVE-2023-38545 and CVE-2023-38546.

Potential Impact: SAS applications might be susceptible to buffer overflow and cookie manipulation attacks.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Viya 3.xMicrosoft® Windows® for x643.5Viya 3.5
Linux for x643.5Viya 3.5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.