Problem Note 70606: The MODEL procedure contains a security vulnerability when you specify invalid syntax
Severity: High
Description: PROC MODEL stops processing and generates traceback information with an access violation. This issue can occur when you specify invalid syntax in the PROC MODEL statement.
To circumvent this issue, specify a valid PROC MODEL statement.
Potential Impact: The resulting access violation introduces a potential security risk.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS/ETS | Solaris for x64 | 12.3 | | 9.4 TS1M0 | |
Linux for x64 | 12.3 | | 9.4 TS1M0 | |
HP-UX IPF | 12.3 | | 9.4 TS1M0 | |
64-bit Enabled Solaris | 12.3 | | 9.4 TS1M0 | |
64-bit Enabled AIX | 12.3 | | 9.4 TS1M0 | |
Windows 7 Professional x64 | 12.3 | | 9.4 TS1M0 | |
Windows 7 Enterprise x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2012 Std | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2012 R2 Std | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2012 R2 Datacenter | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2012 Datacenter | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2008 for x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows Server 2008 R2 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 10 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8.1 Pro x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8.1 Pro 32-bit | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8.1 Enterprise x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8.1 Enterprise 32-bit | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8 Pro x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft Windows 8 Enterprise x64 | 12.3 | | 9.4 TS1M0 | |
Microsoft® Windows® for x64 | 12.3 | | 9.4 TS1M0 | |
z/OS | 12.3 | | 9.4 TS1M0 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
When invalid syntax is specified in the PROC MODEL statement, the procedure might stop processing and generate traceback information with an access violation.
Type: | Problem Note |
Priority: | high |
Topic: | Analytics ==> Econometrics Analytics ==> Regression SAS Reference ==> Procedures ==> MODEL
|
Date Modified: | 2024-01-26 13:04:55 |
Date Created: | 2024-01-18 15:09:27 |