IBM Corporation Information for VU#10277

Various shells create temporary files insecurely when using << operator



Vendor Statement

We examined our UNIX shells that ship aith AIX for the redirection operator vulnerability.

Our ksh is not vulnerable.

Our Bourne shell may be vulnerable, but we have asked the developer to review the appropriate
source code to make a final determination.

Our csh is vulnerable, and the problem is being fixed.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.