1. 71
  1.  

  2. 7

    The big question: How? A simple printf inject sounds unlikely, or else it would somehow break for other escape sequences too.

    Edit: Nevermind, see https://lobste.rs/s/yklnww/quick_analysis_for_ssid_format_string_bug for an analysis

    1. 2

      Only if you join it, though.