int sprintf($_1_2 char *, $untainted char *, $_2 ...); int main(void) { $tainted char *s; char buf[100]; sprintf(buf, "%s", s); }
CQual - A tool for adding type qualifiers to C
README linux-lock.c linux-lock.i linux-lock2.c linux-lock2.i lock.c lock2.c lock3.c rcs1.c rcs2.c rcs3.c taint-cast.c taint-const-subtyping.c taint-poly.c taint-varargs.c taint0.c taint1.c taint2.c user0.c user1.c y2k1.c y2k2.c y2k3.c y2k4.c