Knowing this now, I'll be sure to look over all my scripts that use Sys::Syslog and will be sure to pay careful attention in the future to modules that say anything about using printf. However, I was wondering if there was any general rule that I am missing here. It just seems to easy to unknowingly pass something to a module that you don't know uses printf. Is there any way taint mode can check for this? Thanks!
In reply to Format string vulnerability by Mr_Person
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |