Security-sensitive files in publicly writable directories

Security-sensitive files in publicly writable directories

Description

Creating security-sensitive files in shared writable directories such as /tmp, /var/tmp or /dev/shm can let other users interfere with them.

Potential impact

  • Symbolic-link attacks, file replacement, race conditions and data tampering.

Remediation

Create a service-specific directory with restricted ownership and access, or use an atomic temporary-file API. Changing the pathname alone does not configure permissions.

Examples

Before

c
FILE *f = fopen("/tmp/app.log", "w");

After

c
FILE *f = fopen("/var/lib/app/app.log", "w");

The first excerpt creates a file in a publicly writable directory. For the second, preconfigure /var/lib/app as a service-owned directory with restricted access. Other users must not be able to replace existing files or parent directories. Also enforce file permissions and handle open failures.

References