From 90cbfc96d118d6b55c47392d8ae421434dea8225 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Mon, 25 Feb 2013 17:34:21 +0100 Subject: Make sure to set umask() before calling mkstemp(). Reviewed-by: David Disseldorp Autobuild-User(master): David Disseldorp Autobuild-Date(master): Wed Mar 6 01:16:34 CET 2013 on sn-devel-104 --- source3/libads/kerberos.c | 3 +++ 1 file changed, 3 insertions(+) (limited to 'source3/libads') diff --git a/source3/libads/kerberos.c b/source3/libads/kerberos.c index 50a409c1af..96d194dc31 100644 --- a/source3/libads/kerberos.c +++ b/source3/libads/kerberos.c @@ -833,6 +833,7 @@ bool create_local_private_krb5_conf_for_domain(const char *realm, char *realm_upper = NULL; bool result = false; char *aes_enctypes = NULL; + mode_t mask; if (!lp_create_krb5_conf()) { return false; @@ -906,7 +907,9 @@ bool create_local_private_krb5_conf_for_domain(const char *realm, flen = strlen(file_contents); + mask = umask(S_IRWXO | S_IRWXG); fd = mkstemp(tmpname); + umask(mask); if (fd == -1) { DEBUG(0,("create_local_private_krb5_conf_for_domain: smb_mkstemp failed," " for file %s. Errno %s\n", -- cgit