|
|
Log in / Subscribe / Register

Security hardening for Debian

Security hardening for Debian

Posted Feb 7, 2008 5:37 UTC (Thu) by jimparis (guest, #38647)
Parent article: Security hardening for Debian

For format string attacks, why isn't there a simple option to just disable "%n" processing
entirely?  So few applications actually need it.  You'd still be vulnerable to information
disclosure if you process an untrusted format string, but an actual exploit capable of running
external code should be nigh impossible without %n.


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds