You are here: Foswiki>Tasks Web>Item15198 (06 Aug 2023, MichaelDaum)Edit Attach

Item15198: Default to a secure location for temporary files not vulnerable to symlink attacks

pencil
Priority: Security
Current State: Closed
Released In: 2.1.8
Target Release: patch
Applies To: Engine
Component:
Branches: Release02x01 master
Reported By: MichaelDaum
Waiting For:
Last Change By: MichaelDaum
File::Temp land friends are insecure as per CVE-2011-4116. As this doesn't seem to be solved upstream the next best "fix" is to use a secure location for temporary files ... which we actually have in Foswiki under $Foswiki::cfg{WorkingDir}/tmp. This is far better than to use the system's default location such as /tmp used by anybody on the system.

-- MichaelDaum - 11 Jul 2023

 
Topic revision: r2 - 06 Aug 2023, MichaelDaum
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy