#cwe-787 clear

Binutils srconv output file name construction uses unbounded strcpy/strcat

tar: unsafe strcpy/strcat with environment-derived TMPDIR (xheader.c)