...
Splint Version 3.1.1 can detect violations of this rule.
GCC Compiler Version 4.4.0 can detect violations of this rule when the -Wformat-security flag is used.
Compass/ROSE can detect violations of this rule.
Klocwork Version 8.0.4.16 can detect violations of this rule with the SV.FMTSTR.GENERIC checker.
Related Vulnerabilities
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
...