[splint-discuss] formatconst example?
austin_hastings at yahoo.com
Thu Sep 11 15:14:08 EDT 2003
void foo(const char * format, int value)
/* Format string not known at compile time. */
--- Elise Berger <eberger at cygnacom.com> wrote:
> I am trying to understand what exactly the formatconst flag does. The
> manual has the following text:
> A simpler way to detect format vulnerabilities is to warn for any
> string that
> is unknown at compile time. Splint provides this checking, issuing a
> if the +formatconst
> flag is set and finds any unknown format strings at compile time.
> This can
> produce spurious
> messages, however, because there might be unknown format strings that
> not vulnerable to
> hostile input.
> What is meant by "a format string unknown at compile time?" Does this
> to a format specifier? Can anyone provide an example?
> Any information on the above would be much appreciated.
> Elise T. Berger
> Senior Security Engineer
> CygnaCom Solutions, Inc.
> an Entrust company
> Phone: 703-270-3511 Fax: 703-848-0960
> eberger at cygnacom.com
More information about the splint-discuss