Insecure temporary file creation

Insecure temporary file creation

Description

APIs that generate predictable temporary filenames can expose applications to race conditions and symbolic-link attacks.

Potential impact

  • Overwriting unintended files, information disclosure or privilege escalation.

Remediation

Use mkstemp or a platform-specific API that creates and opens the file atomically, rather than generating only a name. Use the returned file descriptor, handle failure, and close and remove the file when finished.

Examples

Before

c
char name[] = "/tmp/app.XXXXXX";
mktemp(name);
FILE *f = fopen(name, "w");

After

c
char name[] = "/tmp/app.XXXXXX";
int fd = mkstemp(name);

The first excerpt generates a name with mktemp and opens it separately, leaving a race window. The second creates the temporary file atomically.

References