mktemp warning under linux...

Russ Allbery rra at stanford.edu
Mon Mar 4 01:54:42 UTC 2002



William F Maton <wmaton at ryouko.dgim.crc.ca> writes:

> One warning:

> /root/src/news/inn-CURRENT-20020303/lib/libinn.a(inndcomm.o): In function
> `ICCopen':
> /root/src/news/inn-CURRENT-20020303/lib/inndcomm.c:71: the use of `mktemp'
> is dangerous, better use `mkstemp'

> They are scattered about during the compile process.  Here are the
> system's particulars:

Yup, it's a long-standing and known problem.  INN uses its own private
temporary directory, so there isn't a security problem (as long as that
directory is set up properly), but the current handling of temporary files
is very ugly and needs to be cleaned up.  It's one of the projects listed
in TODO.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>


More information about the inn-bugs mailing list