IBM Corporation Information for VU#10277
Various shells create temporary files insecurely when using << operator
- Vendor Information Help Date Notified: 14 May 2001
- Statement Date:
- Date Updated: 13 Jun 2001
We examined our UNIX shells that ship aith AIX for the redirection operator vulnerability.
Our ksh is not vulnerable.
Our Bourne shell may be vulnerable, but we have asked the developer to review the appropriate
source code to make a final determination.
Our csh is vulnerable, and the problem is being fixed.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.