Description
Granting group or other-user write access to a security-sensitive file lets untrusted users with those permissions change its contents.
Potential impact
- Configuration tampering, privilege escalation, or replacement of code or data.
Remediation
Create sensitive files with minimal permissions, generally 0600 or a more restrictive mode. Check file ownership and who can modify parent directories too.
Examples
Before
c
open("/var/app/config", O_CREAT | O_WRONLY, 0666);
After
c
open("/var/app/config", O_CREAT | O_WRONLY, 0600);
The first excerpt requests group and other-user write bits for a new file. Actual permissions also depend on the umask and ACLs. The second requests owner read/write access only.
The mode argument to open does not change an existing file's permissions. Check the ownership and actual permissions of existing files separately. These excerpts assume a trusted directory and path.