Description
Creating security-sensitive files in shared writable directories such as /tmp, /var/tmp or /dev/shm can let other users interfere with them.
Potential impact
- Symbolic-link attacks, file replacement, race conditions and data tampering.
Remediation
Create a service-specific directory with restricted ownership and access, or use an atomic temporary-file API. Changing the pathname alone does not configure permissions.
Examples
Before
c
FILE *f = fopen("/tmp/app.log", "w");
After
c
FILE *f = fopen("/var/lib/app/app.log", "w");
The first excerpt creates a file in a publicly writable directory. For the second, preconfigure /var/lib/app as a service-owned directory with restricted access. Other users must not be able to replace existing files or parent directories. Also enforce file permissions and handle open failures.