Security hardening for Debian
Security hardening for Debian
Posted Feb 7, 2008 5:37 UTC (Thu) by jimparis (guest, #38647)Parent article: Security hardening for Debian
For format string attacks, why isn't there a simple option to just disable "%n" processing entirely? So few applications actually need it. You'd still be vulnerable to information disclosure if you process an untrusted format string, but an actual exploit capable of running external code should be nigh impossible without %n.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
