FTBFS if "-Werror=format-security" flag is used

Ralf Corsepius rc040203 at freenet.de
Thu Dec 5 10:00:33 UTC 2013


On 12/05/2013 10:26 AM, Björn Persson wrote:
> Brendan Jones wrote:
>> Patching is not a problem. Unnecessary is the question. Explain to me
>> (not you in particular Rahul) how these printf's can possibly be
>> exploited?

I believe to be able to prove GCC is producing bogus warnings:

Cf. https://bugzilla.redhat.com/show_bug.cgi?id=1037293
(This is a trimmed down example of a real world case).

AFAIU Jacub, the only issue with this code is GCC hitting is 
implementation limitations, which is causing it to produce a bogus 
warning/error.

Ralf



More information about the devel mailing list