User Supplied format string bug
 
Format String Vulnerabilities in Perl Programs
Steve Christey
December 2005
English
Advances in format string exploitation
Gerardo Richarte, Ricardo Quesada
July 2002
English
Multiple vulnerabilities in stack smashing protection technologies
Gerardo Richarte
April 2002
English
Howto remotely and automatically exploit a format bug
Frédéric Raynal
April 2002
English

 
Format String Attack on alpha system
Seunghyun Seo (truefinder)
September 2001
English
Format String Technique
sloth@nopninjas.com
November 2001
English

 
Windows 2000 Format String Vulnerabilities
David Litchfield,@stake
2001
English-MSWordDoc.zip(David,I dont like word documents!)
Detecting Format-String Vulnerabilities with Type Qualifiers
Umesh Shankar, Kunal Talwar, Jeffrey S. Foster, and David Wagner. 
10th USENIX Security Symposium, August 2001
English-PDF  English.PS.gz
Exploiting Format Strings Vulnerabilities
scut  [team teso]
24 March 2001
English-PDF-1.1TGZ:PDF+sources (German html/sources)
Very Good.
More info on format bugs 
Pascal Bouchareine
July 2000
English Español
Good.
Format String Attacks
Tim Newsham
Guardent Inc, September 2000 
TextPDF
Incomplete text.
Format Bugs: What are they, Where did they come from,...How to exploit them 
Lamagra
http://lamagra.seKure.de
EnglishEspañol
Good
Format String Bug Analysis
Andreas Thuemmel
Securityfocus , March 2001
PDF
Simple.
What are format bugs ?
Christophe BLAESS Christophe GRENIERFrédéreric RAYNAL 
March 2001
EnglishFrench
Paper sobre format bugs
venomous/rdC
December 2000
Español
Exploiting the Libc Locale Subsystem Format String Vulnerability on Solaris/SPARC
Solar Eclipse
November 2000 
Text
Interesting.
glibc-2.1.2's printf segfaults on unreasonable format string. 
-
<Mail Archive glibc-buglist> 
Read this, *printf implementation bugs are other way to exploit usfs vulnerability.
 The Open Group, fprintf, printf, snprintf, sprintf - print formatted output  ,Copyright © 1997 
-
The Single UNIX ® Specification, Version 2 
HTML
Learn to use printf after trying to exploit it :)