Comment by userbinator
12 years ago
It's only a vulnerability if the user can control the format string. Otherwise it's a useful way of getting the lengths of things; but ironically it's not paying attention to lengths that also causes buffer overflow vulnerabilities...
No comments yet
Contribute on Hacker News ↗