PHP 4.0 Bug #5744 Updated: tempnam() possibly used unsafely

From: Date: Mon, 11 Sep 2000 22:46:52 +0000
Subject: PHP 4.0 Bug #5744 Updated: tempnam() possibly used unsafely
Groups: php.dev 
Request: Send a blank email to php-dev+get-32892@lists.php.net to get a copy of this message
ID: 5744 Updated by: stas Reported By: cahagn_o@epita.fr Status: Closed Bug Type: Compile Warning Assigned To: joey Comments: Closed by user request Previous Comments: --------------------------------------------------------------------------- [2000-09-10 13:38:27] joey@php.net Well, I'm pretty sure Zeev's patch will stand up against anything /I/ have to say. :) --------------------------------------------------------------------------- [2000-09-10 05:18:14] cahagn_o@epita.fr I compiled 200009100045 and there're no more warnings, config.log recongizes mktemp(): configure:6238: checking for mkstemp configure:6266: gcc -o conftest -g -O2 -I/usr/pkg/include -L/usr/pkg/lib conft est.c -lresolv -lm -lcrypt -lresolv 1>&5 php compiles without warnings and seems to run fine so far. I tested it because ChangeLog mentioned Zeev had modified configuration files to check for mkstemp() However, joey says that it might be possible to use tmpfile(), so I don't know if this bug should be closed or not. --------------------------------------------------------------------------- [2000-09-06 14:21:06] joey@php.net This will require some kind of major changes. man mkstemp says: Don't use this function, use tmpfile(3) instead. It's better defined and more portable. The problem is that tmpfile returns a file descriptor to an already opened file, which is not what is expected by these portions of code. --------------------------------------------------------------------------- [2000-09-05 07:25:38] cahagn_o@epita.fr With snaphost php4-200009050245, reflecting Zeev's security fixes, the warnings changed a bit (the lines are different, that's all): file.c:595: warning: tempnam() possibly used unsafely, consider using mkstemp() rfc1867.c:329: warning: tempnam() possibly used unsafely, consider using mkstemp() --------------------------------------------------------------------------- [2000-09-04 20:27:26] sniper@php.net Is this still happening with latest CVS?? --Jani --------------------------------------------------------------------------- The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online. Full Bug description available at: http://bugs.php.net/?id=5744

« previous php.dev (#32892) next »