Format String Vulnerabilities

Tags:

Exploiting Format String Vulnerabilities

How does a format string vulnerability look like ?

     Wrong usage:

int
func (char *user)
{
            printf (user);
}

     Ok:

int
func (char *user)
{
            printf (“%s”, user);
}