about summary refs log tree commit diff
path: root/nixpkgs/pkgs/tools/backup/store-backup/CVE-2020-7040.patch
blob: 9b78f9bab95fafaf2b80027dd9e5520f2125d6bc (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
Index: storeBackup/lib/fileDir.pl
===================================================================
--- storeBackup.orig/lib/fileDir.pl
+++ storeBackup/lib/fileDir.pl
@@ -21,7 +21,7 @@
 
 
 use Digest::MD5 qw(md5_hex);
-use Fcntl qw(O_RDWR O_CREAT);
+use Fcntl qw(O_RDWR O_CREAT O_WRONLY O_EXCL);
 use Fcntl ':mode';
 use POSIX;
 use Cwd 'abs_path';
@@ -482,7 +482,7 @@ sub checkLockFile
 		  '-str' => ["creating lock file <$lockFile>"]);
 
     &::checkDelSymLink($lockFile, $prLog, 0x01);
-    open(FILE, '>', $lockFile) or
+    sysopen(FILE, $lockFile, O_WRONLY | O_CREAT | O_EXCL) or
 	$prLog->print('-kind' => 'E',
 		      '-str' => ["cannot create lock file <$lockFile>"],
 		      '-exit' => 1);