Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Wiki Markup
Unfortunately, this solution is still non-compliant because it violates \[[FIO32-C|TMPxx-C. Temporary file names must be unique when the file is created]\], \[[FI040-C|TMP32-C. Temporary files must be opened with exclusive access]\], \[[FI041-C|TMP31-C. Temporary files must have an unpredictable name]\], and \[[FI042-C|TMP33-C. Temporary files must be removed before the program exits]\].

...

Wiki Markup
This solution is also non-compliant because it violates \[[FIO32-C|TMPxx-C. Temporary file names must be unique when the file is created]\] and \[[FI042-C|TMP33-C. Temporary files must be removed before the program exits]\].

...

Wiki Markup
This solution is also non-compliant because it violates \[[FIO32-C|TMPxx-C. Temporary file names must be unique when the file is created]\] and \[[FI042-C|TMP33-C. Temporary files must be removed before the program exits]\].

...

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

TMP30-C

3 (high)

2 (probable)

1 (high)

P6

L2

Related Vulnerabilities

Search for Examples of vulnerabilities resulting from the violation of this rule can be found on the CERT website.

References

Wiki Markup
\[[ISO/IEC 9899-1999|AA. C References#ISO/IEC 9899-1999]\] Sections 7.19.4.4, "The {{tmpnam}} function," 7.19.4.3, "The {{tmpfile}} function," and 7.19.5.3, "The {{fopen}} function"
\[[ISO/IEC TR 24731-2006|AA. C References#ISO/IEC TR 24731-2006]\] Sections 6.5.1.2, "The {{tmpnam_s}} function," 6.5.1.1, "The {{tmpfile_s}} function," and 6.5.2.1, "The {{fopen_s}} function"
\[[Open Group 04|AA. C References#Open Group 04]\] [mktemp()|http://www.opengroup.org/onlinepubs/000095399/functions/mktemp.html], [mkstemp()|http://www.opengroup.org/onlinepubs/009695399/functions/mkstemp.html], [open()|http://www.opengroup.org/onlinepubs/009695399/functions/open.html]
\[[Seacord 05a|AA. C References#Seacord 05a]\] Chapter 3, "File I/O"
\[[Wheeler 03|AA. C References#Wheeler 03]\] [Chapter 7, "Structure Program Internals and Approach"|http://www.dwheeler.com/secure-programs/Secure-Programs-HOWTO/avoid-race.html#TEMPORARY-FILES]
\[[Viega 03|AA. C References#Viega 03]\] Section 2.1, "Creating Files for Temporary Use"
\[[Kennaway 00|AA. C References#Kennaway 00]\]
\[[HP 03|AA. C References#HP 03]\]