Description
APIs that generate predictable temporary filenames can expose applications to race conditions and symbolic-link attacks.
Potential impact
- Overwriting unintended files, information disclosure or privilege escalation.
Remediation
Use mkstemp or a platform-specific API that creates and opens the file atomically, rather than generating only a name. Use the returned file descriptor, handle failure, and close and remove the file when finished.
Examples
Before
c
char name[] = "/tmp/app.XXXXXX";
mktemp(name);
FILE *f = fopen(name, "w");
After
c
char name[] = "/tmp/app.XXXXXX";
int fd = mkstemp(name);
The first excerpt generates a name with mktemp and opens it separately, leaving a race window. The second creates the temporary file atomically.