SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70606: The MODEL procedure contains a security vulnerability when you specify invalid syntax

DetailsHotfixAboutRate It

Severity: High

Description: PROC MODEL stops processing and generates traceback information with an access violation. This issue can occur when you specify invalid syntax in the PROC MODEL statement.

To circumvent this issue, specify a valid PROC MODEL statement.

Potential Impact: The resulting access violation introduces a potential security risk.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS/ETSSolaris for x6412.39.4 TS1M0
Linux for x6412.39.4 TS1M0
HP-UX IPF12.39.4 TS1M0
64-bit Enabled Solaris12.39.4 TS1M0
64-bit Enabled AIX12.39.4 TS1M0
Windows 7 Professional x6412.39.4 TS1M0
Windows 7 Enterprise x6412.39.4 TS1M0
Microsoft Windows Server 2012 Std12.39.4 TS1M0
Microsoft Windows Server 2012 R2 Std12.39.4 TS1M0
Microsoft Windows Server 2012 R2 Datacenter12.39.4 TS1M0
Microsoft Windows Server 2012 Datacenter12.39.4 TS1M0
Microsoft Windows Server 2008 for x6412.39.4 TS1M0
Microsoft Windows Server 2008 R212.39.4 TS1M0
Microsoft Windows 1012.39.4 TS1M0
Microsoft Windows 8.1 Pro x6412.39.4 TS1M0
Microsoft Windows 8.1 Pro 32-bit12.39.4 TS1M0
Microsoft Windows 8.1 Enterprise x6412.39.4 TS1M0
Microsoft Windows 8.1 Enterprise 32-bit12.39.4 TS1M0
Microsoft Windows 8 Pro x6412.39.4 TS1M0
Microsoft Windows 8 Enterprise x6412.39.4 TS1M0
Microsoft® Windows® for x6412.39.4 TS1M0
z/OS12.39.4 TS1M0
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.