Severity: High
Description: Under certain conditions, an error might occur that results in a segmentation violation or buffer overflow in Base SAS or SAS/STAT. Although the issue is more common on these products, it might occur on other SAS products.
Potential Impact: This vulnerability could lead to a denial of service or arbitrary code execution.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | Base SAS | z/OS | 9.4_M7 | 9.4 TS1M7 | ||
z/OS 64-bit | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft® Windows® for x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Enterprise 32-bit | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Enterprise x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Pro 32-bit | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Pro x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Enterprise 32-bit | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Enterprise x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Pro 32-bit | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Pro x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 10 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows 11 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 R2 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 for x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 Datacenter | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 R2 Datacenter | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 R2 Std | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 Std | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2016 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2019 | 9.4_M7 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2022 | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Enterprise 32 bit | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Enterprise x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Home Premium 32 bit | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Home Premium x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Professional 32 bit | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Professional x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Ultimate 32 bit | 9.4_M7 | 9.4 TS1M7 | ||||
Windows 7 Ultimate x64 | 9.4_M7 | 9.4 TS1M7 | ||||
64-bit Enabled AIX | 9.4_M7 | 9.4 TS1M7 | ||||
64-bit Enabled Solaris | 9.4_M7 | 9.4 TS1M7 | ||||
HP-UX IPF | 9.4_M7 | 9.4 TS1M7 | ||||
Linux for x64 | 9.4_M7 | 9.4 TS1M7 | ||||
Solaris for x64 | 9.4_M7 | 9.4 TS1M7 | ||||
SAS System | SAS/STAT | z/OS | 15.2 | 9.4 TS1M7 | ||
Microsoft® Windows® for x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Enterprise 32-bit | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Enterprise x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Pro 32-bit | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8 Pro x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Enterprise 32-bit | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Enterprise x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Pro 32-bit | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 8.1 Pro x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 10 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 11 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 R2 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2008 for x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 Datacenter | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 R2 Datacenter | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 R2 Std | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2012 Std | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2016 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2019 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows Server 2022 | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Enterprise 32 bit | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Enterprise x64 | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Home Premium 32 bit | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Home Premium x64 | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Professional 32 bit | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Professional x64 | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Ultimate 32 bit | 15.2 | 9.4 TS1M7 | ||||
Windows 7 Ultimate x64 | 15.2 | 9.4 TS1M7 | ||||
64-bit Enabled AIX | 15.2 | 9.4 TS1M7 | ||||
64-bit Enabled Solaris | 15.2 | 9.4 TS1M7 | ||||
HP-UX IPF | 15.2 | 9.4 TS1M7 | ||||
Linux for x64 | 15.2 | 9.4 TS1M7 | ||||
Solaris for x64 | 15.2 | 9.4 TS1M7 | ||||
Microsoft Windows 95/98 | 9.4 | |||||
Microsoft Windows 2000 Advanced Server | 9.4 | |||||
Microsoft Windows 2000 Datacenter Server | 9.4 | |||||
Microsoft Windows 2000 Server | 9.4 | |||||
Microsoft Windows 2000 Professional | 9.4 | |||||
Microsoft Windows NT Workstation | 9.4 | |||||
Microsoft Windows Server 2003 Datacenter Edition | 9.4 | |||||
Microsoft Windows Server 2003 Enterprise Edition | 9.4 | |||||
Microsoft Windows Server 2003 Standard Edition | 9.4 | |||||
Microsoft Windows Server 2003 for x64 | 9.4 | |||||
Microsoft Windows XP Professional | 9.4 | |||||
Windows Millennium Edition (Me) | 9.4 | |||||
Windows Vista | 9.4 | |||||
Windows Vista for x64 | 9.4 | |||||
SAS System | SAS Viya 3.x | Microsoft® Windows® for x64 | 3.5 | Viya 3.5 | ||
Linux for x64 | 3.5 | Viya 3.5 |
Viya on Linux: An update for this issue is available for SAS Viya 3.5. For instructions on how to access and apply software updates, see the Updating Your SAS Viya software section in the SAS Viya 3.5 for Linux Deployment Guide at
http://documentation.sas.com/?softwareId=administration&softwareVersion=3.5&softwareContextId=softwareUpdatesA fix for this issue for Base SAS 9.4_M8 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/L8X.html#70709A fix for this issue for Base SAS User Interface 9.4_M8 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/N3S.html#70709A fix for this issue for SAS/STAT 15.3 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/L9L.html#70709A fix for this issue for SAS/GRAPH 9.4_M8 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/L9R.html#70709A fix for this issue for SAS/ACCESS Interface to PC Files 9.4_M8 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/M4D.html#70709A fix for this issue for SAS ODS Graphics C Renderer 9.47 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/N5C.html#70709A fix for this issue for Base SAS 9.4_M7 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/I9R.html#70709A fix for this issue for SAS/GRAPH 9.4_M7 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/L2F.html#70709Type: | Problem Note |
Priority: | high |
Date Modified: | 2024-03-14 18:59:24 |
Date Created: | 2024-03-12 16:15:47 |