Re: Use mkstemp() instead of tempnam() in rfc1867.c?

From: Date: Mon, 21 Aug 2000 17:49:03 +0000
Subject: Re: Use mkstemp() instead of tempnam() in rfc1867.c?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-30083@lists.php.net to get a copy of this message
On Mon, 21 Aug 2000, Stanislav Malyshev wrote: > JS>> Right now, main/rfc1867.c uses tempnam() for creating the temporary file > JS>> to store uploads in. Simply wondering if anyone thinks it would bew > JS>> worth rewriting this section to use mkstemp instead? > > That's hard to do, for following reasons: > 1. mkstemp opens file, which doesn't fit current code flow That is no argument. If a specific code has security problems, you don't complain about how hard it is to rewrite it; you simply do it. (This also applies to the pieces of code which use strlcat/strlcpy. These functions are for fixing broken/legacy code quickly.) > 2. win32 doesn't have mkstemp, and we cannot easily define it out because > of 1. I'm not even sure all Unix platforms have mkstemp. Well, so write a mkstemp replacement which uses tempnam and opens the file. This can be easily implemented for Win32 and other platforms which lack a native mkstemp. This is not to say that it must be done. But I want to emphasize that it is possible and feasible. - Sascha

« previous php.dev (#30083) next »