Description
tmpnam-style APIs may produce predictable temporary filenames. Name generation is separate from file creation, leaving a race condition.
Potential impact
- Symbolic-link attacks, arbitrary file overwrites, or information exposure
Remediation
Use an API such as mkstemp that creates the file atomically.
Examples
Before
c
char name[L_tmpnam];
tmpnam(name);
After
c
char name[] = "/tmp/app.XXXXXX";
int fd = mkstemp(name);
Explanation:
- Before: Only a temporary name is generated, leaving a race before the file is created.
- After: Name selection and file creation are atomic.