From: KOSAKI Motohiro Date: 2010-09-24T23:49:24+09:00 Subject: [ruby-core:32547] Re: [Ruby 1.9-Bug#3869][Open] Logger#log does not handle or escape new-line characters. Hi > � �>> logger = Logger.new(STDOUT) > � �>> logger.log Logger::INFO, "hello\nworld" > � �I, [2010-09-23T12:28:09.612508 #6122] �INFO -- : hello > � �world > � � => true > � �>> logger.log Logger::INFO, "Fault detected!\nI, [2010-09-23T12:28:09.612508 #6122] �INFO -- : Fault was false-positive, ignoring ..." > � �I, [2010-09-23T12:32:57.757877 #6122] �INFO -- : Fault detected! > � �I, [2010-09-23T12:28:09.612508 #6122] �INFO -- : Fault was false-positive, ignoring ... > � � => true I doubt this can be used for security abuse. Unix syslog has very similar problem for 10+ years. But It haven't made security issue (as far as I know). So, I'd like to know the reason why you think \n should be escaped. example, If you worry about CVE-2009-4492 like issue, don't we need to consider to refuse all of tainted string instead?