alpine 3.6
misc weakness #63

The software specifies permissions for a security-critical resource in a way that allows the resource to be read or modified by unintended actors.

2

Weakness Breakdown


Warning code(s):

Check when opening files - can an attacker redirect it.

File Name:

./src/Droplet-2.0/libdroplet/src/profile.c

Context:
ctx->event_log = fopen(path, "a+");

The registered trademark Linux® is used pursuant to a sublicense from the Linux Foundation, the exclusive licensee of Linus Torvalds, owner of the mark on a world­wide basis.