Re: Use mkstemp() instead of tempnam() in rfc1867.c?
| From: | Stanislav Malyshev | Date: | Mon, 21 Aug 2000 17:35:30 +0000 |
| Subject: | Re: Use mkstemp() instead of tempnam() in rfc1867.c? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30079@lists.php.net to get a copy of this message | ||
JS>> Right now, main/rfc1867.c uses tempnam() for creating the temporary file
JS>> to store uploads in. Simply wondering if anyone thinks it would bew
JS>> worth rewriting this section to use mkstemp instead?
That's hard to do, for following reasons:
1. mkstemp opens file, which doesn't fit current code flow
2. win32 doesn't have mkstemp, and we cannot easily define it out because
of 1. I'm not even sure all Unix platforms have mkstemp.
3. This is not so much of an issue - to exploit this vulnerability, you
should have at least shell access to the server, and if you do, there are
worse things you could do...
This is not to say this shouldn't be done, this is to explain why it
wasn't.
--
Stanislav Malyshev stas@zend.com
+972-3-6139665 ext.106