Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe
| From: | Alban Hertroys | Date: | Tue, 11 Jul 2000 07:59:59 +0000 |
| Subject: | Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-24166@lists.php.net to get a copy of this message | ||
> ID: 5509
> Updated by: stas
> Reported By: alban.hertroys@ddnh.nl
> Status: Closed
> Bug Type: Misbehaving function
> Assigned To:
> Comments:
>
> This is not a bug. tempnam is not safe, everybody knows that, so don't use it if your
> stuff is security-sensitive.
I'm not talking about security here, but about the safety of the
temp-files of other processes and those of PHP itself. On servers with a
bit of a load, a PHP-script page using tempnam could be requested twice
in the time that it takes to generate a filename and open a
filedescriptor using it, with a good chance of the one page overwriting
the temp-file of the other page. This is especially true for interpreted
languages, as both operations take more time.
IMHO, it would be better to have an implementation of mkstemp() than one
of tempnam().
The difference between the two functions is
(these are C versions of the two functions):
char *tempnam(const char *dir, const char *prefix);
returns a character array.
int mkstemp(char *template);
returns a file descriptor.
If you compile a C program (using gcc) that uses tempnam, you get a
warning saying:
"tempnam() is not safe. Use mkstemp() instead."
I would not assume that this is a triviality, C and UNIX have been in
development for decennia. These developers know what they are talking
about.
I have to admit though, that I am not an expert in this aspect. I am
just a somewhat above mediocre C-programmer and more like a novice
concerning PHP.