Re: Use mkstemp() instead of tempnam() in rfc1867.c?

From: Date: Mon, 21 Aug 2000 17:35:30 +0000
Subject: Re: Use mkstemp() instead of tempnam() in rfc1867.c?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-30079@lists.php.net to get a copy of this message
JS>> Right now, main/rfc1867.c uses tempnam() for creating the temporary file JS>> to store uploads in. Simply wondering if anyone thinks it would bew JS>> worth rewriting this section to use mkstemp instead? That's hard to do, for following reasons: 1. mkstemp opens file, which doesn't fit current code flow 2. win32 doesn't have mkstemp, and we cannot easily define it out because of 1. I'm not even sure all Unix platforms have mkstemp. 3. This is not so much of an issue - to exploit this vulnerability, you should have at least shell access to the server, and if you do, there are worse things you could do... This is not to say this shouldn't be done, this is to explain why it wasn't. -- Stanislav Malyshev stas@zend.com +972-3-6139665 ext.106

« previous php.dev (#30079) next »