3 ms·
why is mktemp insecure?
by make3 5y ago
why is mktemp insecure?
- goodside 5y agoPython mktemp has been deprecated since 2003. I there’s a race condition that allows a malicious process to slip in a file or symlink with different permissions at the path mktemp returns.
- tyingq 5y agoJust for clarity, the race condition seems deliberate. It just returns a path and leaves it to you to create the file.
- goodside 5y agoYes — the core problem is you can’t be guaranteed exclusive write access to a path without actually creating a file or directory. The warning in the docs (https://docs.python.org/3/library/tempfile.html#tempfile.mktemp https://docs.python.org/3/library/tempfile.html#tempfile.mkt...) aims to show an example of how to get “just a path” by making and deleting a NamedTemporaryFile, but the example is confusing and has unnecessary steps. Seems like you could just do `with NamedTemporaryFile() as f: path = f.name`. Also, the warning seems to imply using `NamedTemporaryFile` addresses the race condition, but it doesn’t — the problem exists even for “secure” methods any time you re-use the path after cleanup.