[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Android port

From: Po Lu
Subject: Re: Android port
Date: Sun, 06 Aug 2023 20:16:14 +0800
User-agent: Gnus/5.13 (Gnus v5.13)

Bruno Haible <bruno@clisp.org> writes:

> Rationale: I cannot guarantee that Gnulib will be able to support %n
> in the long run. The "security-aware community" are filing CVEs here and
> there; %n is among their targets (it has already been disabled from libc
> on Ubuntu, macOS, and MSVC); and I don't know when they will discover
> that Gnulib still enables it.

Then Gnulib should disregard their whims and move on.  If a program
employs %n incorrectly, and that exposes a security vulnerability as a
result, the fault lies with the authors of said program rather than

reply via email to

[Prev in Thread] Current Thread [Next in Thread]