Format string bugs TL;DR: User-controlled format → arbitrary read (%s/%x) and arbitrary write (%n). Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO