<?xml version="1.0"?>
<scan-result xmlns="https://svs-www.informatik.uni-hamburg.de/softsec/projects/sectoolers/ns/scan-result/0.9/">
  <timestamp>2006-12-14T13:28:25+01:00
</timestamp>
  <host>sectools
</host>
  <files>
    <file>/usr/include/alloca.h</file>
    <file>/usr/include/bits/sys_errlist.h</file>
    <file>/usr/include/err.h</file>
    <file>/usr/include/gconv.h</file>
    <file>/usr/include/libio.h</file>
    <file>/usr/include/stdio.h</file>
    <file>/usr/include/stdlib.h</file>
    <file>/usr/include/sys/select.h</file>
    <file>/usr/include/sys/sysmacros.h</file>
    <file>/usr/lib/gcc/i486-linux-gnu/4.0.3/include/stddef.h</file>
    <file>/usr/local/share/cqual/linux-syscalls.cq</file>
    <file>/usr/local/share/cqual/prelude.cq</file>
    <file>/usr/local/share/cqual/proto-noderef.cq</file>
    <file>formatstring.c</file>
    <file>examples/main.c</file>
  </files>
  <tools>
    <tool>
      <name>cqual</name>
      <version>v0.991-modified</version>
      <tool-config>
        <command-line>/usr/local/bin/gcqual -cqual /usr/local/bin/cqual -fxml-mode -fpoly formatstring.c</command-line>
      </tool-config>
    </tool>
                <tool>
                        <name>boon</name>
                        <version>1.0</version>
                        <tool-config></tool-config>
                        <command-line>--xml examples/main.c </command-line>
                </tool>
  </tools>
  <configuration/>
  <problems>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>91</line>
        <field>null</field>
        <text>multiple polymorphic types for ``memcpy'' -- not checking for consistency</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>110</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>115</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>131</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>132</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>134</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>135</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>139</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>141</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>142</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>143</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>147</line>
        <field>null</field>
        <text>ignoring static prelude declaration -- conflict with non-static prelude declaration</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>/usr/local/share/cqual/proto-noderef.cq</file>
        <line>149</line>
        <field>null</field>
        <text>multiple polymorphic types for ``strstr'' -- not checking for consistency</text>
      </location>
      <trace/>
    </problem>
    <problem>
      <toolname>cqual</toolname>
      <severity>1.0</severity>
      <probability>0.5</probability>
      <category>type</category>
      <location>
        <file>formatstring.c</file>
        <line>23</line>
        <field>*env</field>
        <text>incompatible types in assignment</text>
      </location>
      <trace>
        <location>
          <file>/usr/local/share/cqual/prelude.cq</file>
          <line>58</line>
          <text>$tainted &lt;= *getenv_ret</text>
        </location>
        <location>
          <file>formatstring.c</file>
          <line>23</line>
          <text>*getenv_ret &lt;= *getenv_ret@23</text>
        </location>
        <location>
          <file>formatstring.c</file>
          <line>23</line>
          <text>*getenv_ret@23 &lt;= *env</text>
        </location>
        <location>
          <file>formatstring.c</file>
          <line>26</line>
          <text>*env &lt;= *printf_arg1@26</text>
        </location>
        <location>
          <file>formatstring.c</file>
          <line>26</line>
          <text>*printf_arg1@26 &lt;= *printf_arg1</text>
        </location>
        <location>
          <file>/usr/local/share/cqual/prelude.cq</file>
          <line>33</line>
          <text>*printf_arg1 &lt;= $untainted</text>
        </location>
      </trace>
    </problem>
                <problem>
                        <toolname>boon</toolname>
                        <severity>1</severity>
                        <probability>60</probability>
                        <category>memorybounds</category>
                        <location>
                                <file>/home/christian/tools-xml/boon-1.1/examples/main.c</file>
                                <line>4</line>
                                <function>main</function>
                                <field>x</field>
                                <text></text>
                                <explanation></explanation>
                        </location>
                </problem>
  </problems>
</scan-result>

