note 37762 added to function.tempnam
| From: | phpdoc at rickbradley dot com | Date: | Tue, 25 Nov 2003 20:54:28 +0000 |
| Subject: | note 37762 added to function.tempnam | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-60984@lists.php.net to get a copy of this message | ||
The "newtempnam" recipe provided below (posted by "tempnam" on "
23-Jul-2003 08:56") has at least one race condition. The while loop checks to make sure that
the file in question doesn't exist, and then goes and creates the file. In between the
existence test and the fopen() call there is an opportunity for an attacker to create the file in
question.
This is a classic race-condition, and while it seems difficult to exploit there are a number of
well-known attacks against this kind of sloppy file creation.
The atomic primitives necessary to implement secure file creation are not available at the language
level in PHP. This further underscores the need for PHP-language developers to rely on the
language's security primitives (including tempnam() and tempfile()) instead of rolling their
own.
----
Manual Page -- http://www.php.net/manual/en/function.tempnam.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37762
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37762&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37762&report=yes
Search -- http://master.php.net/manage/user-notes.php