RFR: JDK-8262199: TOCTOU in jli args.c [v2]
Christoph Langer
clanger at openjdk.java.net
Tue Feb 23 14:33:09 UTC 2021
On Tue, 23 Feb 2021 14:30:17 GMT, Matthias Baesken <mbaesken at openjdk.org> wrote:
>> Sonar reports a finding in args.c, where a file check is done .
>> Stat performs a check on file, and later fopen is called on the file :
>> https://sonarcloud.io/project/issues?id=shipilev_jdk&languages=c&open=AXck8CL0BBG2CXpcnhtM&resolved=false&types=VULNERABILITY
>>
>> The coding could be slightly rewritten so that the potential TOCTOU is removed (however I do not think that it is such a big issue).
>
> Matthias Baesken has updated the pull request incrementally with one additional commit since the last revision:
>
> Small changes
Marked as reviewed by clanger (Reviewer).
-------------
PR: https://git.openjdk.java.net/jdk/pull/2692
More information about the core-libs-dev
mailing list