[CVE-2019-12450]gfile: Limit access to files when copying 23/207323/1 accepted/tizen/unified/20190604.014623 submit/tizen/20190603.073640
authorOndrej Holy <oholy@redhat.com>
Thu, 23 May 2019 08:41:53 +0000 (10:41 +0200)
committerDonghun Kwak <dh0128.kwak@samsung.com>
Mon, 3 Jun 2019 07:27:15 +0000 (07:27 +0000)
commit6e5e8aaa843238ed8c3125ccd58a474789cff2d9
treea0f2d5cedc366f04993846c55308fc89496a8bab
parent9492ecd804a39c7a2b1d4a62dac4e034988eaf80
[CVE-2019-12450]gfile: Limit access to files when copying

file_copy_fallback creates new files with default permissions and
set the correct permissions after the operation is finished. This
might cause that the files can be accessible by more users during
the operation than expected. Use G_FILE_CREATE_PRIVATE for the new
files to limit access to those files.

Change-Id: Id071a47323fcd0690dec6a5d519d5ab4f2f43562
Signed-off-by: Hyunjee Kim <hj0426.kim@samsung.com>
(cherry picked from commit ec54d211518bf3c2f397f565088a7054219f194e)
gio/gfile.c