Dom, 2008-12-28 às 00:42 -0800, Kees Cook escreveu: > Hi, > > I'd like to seek advice before I perform a mass-bug filing for this > unstable (though semi-common) use of "sprintf" and "snprintf": > > sprintf(buf, "%s foo %d %d", buf, var1, var2); > > This is used in many upstreams to perform a format-string-handling > version of strcat. [...] This will be reported upstream?