Casper.Dik at sun.com wrote:

>
> >     If not used carefully, the system(3C) function may be responsible for
> >     the following security concerns:
> >
> >      + Execution of the command is affected by the PATH, IFS and other
> >        environment variables.
>
> None of our current shells evaluates the IFS environment variable.

The Bourne Shell (bin/sh) does.

J?rg

-- 
 EMail:joerg at schily.isdn.cs.tu-berlin.de (home) J?rg Schilling D-13353 Berlin
       js at cs.tu-berlin.de                (uni)  
       joerg.schilling at fokus.fraunhofer.de (work) Blog: 
http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/private/ ftp://ftp.berlios.de/pub/schily

Reply via email to