Glossary
Format-string vulnerability
A bug where untrusted input is passed as the format argument of printf-style functions, letting it read or write memory through conversion specifiers (CWE-134).
A format-string vulnerability (CWE-134) arises when a program calls a printf-family function with attacker-influenced data as the format string, for example printf(user_input) instead of printf("%s", user_input). Conversion specifiers in the input then make the function read values it was never given, leaking memory contents and addresses, and the %n specifier can write to memory.
Compilers flag the pattern with -Wformat -Wformat-security, FORTIFY_SOURCE rejects %n in writable format strings, and annotating wrappers with __attribute__((format(printf, ...))) extends the checks to custom logging functions. See integer overflows and format strings.