SAS SASTCPD Local Root Code...

- AV AC AU C I A
发布: 2002-01-30
修订: 2025-04-13

sastcpd is a "Job Spawner" included with the base installation of the SAS Software infrastructure. It is available for various platforms, including Unix, Linux, and Microsoft operating systems. sastcpd passes environment variables directly to an execve call. As sastcpd is installed suid root by default, this can lead to the execution of arbitrary programs as the root user. Exploitation of this vulnerability will lead directly to local compromise of the root user.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息