scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.
https://sourceware.org/git/?p=glibc.git%3Ba=commitdiff%3Bh=3f8cc204fdd0
https://sourceware.org/git/?p=glibc.git%3Ba=commitdiff%3Bh=20b38e0
https://sourceware.org/bugzilla/show_bug.cgi?id=13138#c4