There is a vulnerability in the below program that allows arbitrary programs to be executed, can you find it?
asprintf(&buffer, "/bin/echo %s is cool", getenv("USER"));
printf("about to call system(\"%s\")\n", buffer);
We have control of the $USER variable. We can chain /bin/getflag by prefixing $USER with the semi-colon; This ends the echo command prematurely, and the system will continue to execute the rest of our string.