On 12/04/2013 04:56 PM, Brendan Jones wrote: > Patching is not a problem. Unnecessary is the question. Explain to me > (not you in particular Rahul) how these printf's can possibly be exploited? char *output; output = get_user_input(...); printf(output); What happens when the user enters %n? -- ======================================================================== Ian Pilcher arequipeno@xxxxxxxxx Sent from the cloud -- where it's already tomorrow ======================================================================== -- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct