 
                            ...
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CodeSonar | 
 | IO.INJ.FMT MISC.FMT | Format String Injection Format String | ||||||
| 
 | |||||||||
| Coverity | 6.5 | TAINTED_STRING_WARNING | Fully implemented | ||||||
| 5.0 | |||||||||
| GCC | 
 | Can detect violations of this rule when the  | |||||||
| 
 | SV.FMTSTR.GENERIC | ||||||||
| 
 | 86 D | Partially implemented | |||||||
| 
 | 
...
Related Guidelines
| CERT C++ Secure Coding Standard | VOID FIO30-CPP. Exclude user input from format strings | 
| CERT Oracle Secure Coding Standard for Java | IDS06-J. Exclude unsanitized user input from format strings | 
| CERT Perl Secure Coding Standard | IDS30-PL. Exclude user input from format strings | 
| ISO/IEC TR 24772:2013 | Injection [RST] | 
| ISO/IEC TS 17961:2013 | Including tainted or out-of-domain input in a format string [usrfmt] | 
| MITRE CWE | CWE-134, Uncontrolled Format String | 
...