PHP 4.0 Bug #5744 Updated: tempnam() possibly used unsafely
| From: | Bug Database | Date: | Mon, 11 Sep 2000 22:46:52 +0000 |
| Subject: | PHP 4.0 Bug #5744 Updated: tempnam() possibly used unsafely | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32892@lists.php.net to get a copy of this message | ||
ID: 5744
Updated by: stas
Reported By: cahagn_o@epita.fr
Status: Closed
Bug Type: Compile Warning
Assigned To: joey
Comments:
Closed by user request
Previous Comments:
---------------------------------------------------------------------------
[2000-09-10 13:38:27] joey@php.net
Well, I'm pretty sure Zeev's patch will stand up against
anything /I/ have to say. :)
---------------------------------------------------------------------------
[2000-09-10 05:18:14] cahagn_o@epita.fr
I compiled 200009100045 and there're no more warnings,
config.log recongizes mktemp():
configure:6238: checking for mkstemp
configure:6266: gcc -o conftest -g -O2 -I/usr/pkg/include
-L/usr/pkg/lib conft
est.c -lresolv -lm -lcrypt -lresolv 1>&5
php compiles without warnings and seems to run fine so far.
I tested it because ChangeLog mentioned Zeev had modified
configuration files to check for mkstemp()
However, joey says that it might be possible to use
tmpfile(), so I don't know if this bug should be closed or not.
---------------------------------------------------------------------------
[2000-09-06 14:21:06] joey@php.net
This will require some kind of major changes.
man mkstemp says:
Don't use this function, use tmpfile(3) instead. It's
better defined and more portable.
The problem is that tmpfile returns a file descriptor
to an already opened file, which is not what is expected
by these portions of code.
---------------------------------------------------------------------------
[2000-09-05 07:25:38] cahagn_o@epita.fr
With snaphost php4-200009050245, reflecting Zeev's security fixes, the warnings changed a bit
(the lines are different, that's all):
file.c:595: warning: tempnam() possibly used unsafely, consider using mkstemp()
rfc1867.c:329: warning: tempnam() possibly used unsafely, consider using mkstemp()
---------------------------------------------------------------------------
[2000-09-04 20:27:26] sniper@php.net
Is this still happening with latest CVS??
--Jani
---------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view the rest of the comments,
please view the bug report online.
Full Bug description available at: http://bugs.php.net/?id=5744