]> git.ipfire.org Git - thirdparty/freeradius-server.git/commit
Annotate fs_check_call (CID #1271307) (#4778)
authorJames Jones <jejones3141@gmail.com>
Tue, 18 Oct 2022 17:15:55 +0000 (12:15 -0500)
committerGitHub <noreply@github.com>
Tue, 18 Oct 2022 17:15:55 +0000 (13:15 -0400)
commitc96879bee6473452ea854af74dbc44f2f1e122a2
tree5f6e9b91809022c7a3578f8c7451003039826d3f
parentaa2a3a9ccf34b096e6e628e474bf7846d32b285d
Annotate fs_check_call (CID #1271307) (#4778)

The unlink() call (the use of the toctou) does check its return
code. Also, it's not liwted among the UseSet functions in "TOCTTOU
Vulnerabilities in Unix-Style File Systems: An Anatomical Study",
https://www.usenix.org/legacy/events/fast05/tech/full_papers/wei/wei.pdf
src/listen/control/proto_control_unix.c