Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When the code is sprintf(stackbuf, "%s", attacker_supplied_input) in 2025, I expect some serious bowing and scraping.


In fairness, with that level of vulnerability in the code, fixing it is like using paper towels to mop up the ocean.


Yeah if anyone thinks people don't just run searches for `sprintf` they're pretty naive.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: