in reply to Re: Searching for sprintf() bug exploit opportunities in core and CPAN modules
in thread Searching for sprintf() bug exploit opportunities in core and CPAN modules

http://www.phrack.org/phrack/60/p60-0x0a.txt has some info on that.
  • Comment on Re^2: Searching for sprintf() bug exploit opportunities in core and CPAN modules