vendor:
SAS Deployment Manager
by:
Unknown
7,8
CVSS
HIGH
Stack-based Overflow
119
CWE
Product Name: SAS Deployment Manager
Affected Version From: Deployment Manager 9.3.0.0 (Model 12.05, TS1M2)
Affected Version To: SAS Integration Technologies Client 9.31_M1
Patch Exists: Yes
Related CWE: Unknown
CPE: SAS Institute Inc.:SAS_Deployment_Manager:9.3.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
Unknown
SAS Integration Technologies Client 9.31_M1 (SASspk.dll) Stack-based Overflow
The SASspk module (SASspk.dll) version 9.310.0.11307, has a function called 'RetrieveBinaryFile()' which has one parameter called 'bstrFileName' which takes arguments as strings as defined in the function itself as ISPKBinaryFile from the SASPackageRetrieve library. Stack-based buffer overflow was discovered in one of the fuzzing processes that could allow arbitrary code execution by an attacker when exploiting the non-sanitized 'bstrFileName' parameter.
Mitigation:
The vendor has released a patch to address this vulnerability.