Bugzilla – Bug 42
Incomplete Logging Code
Last modified: 2001-06-15 14:12:08 MDT
The logging code (in which the buffer overflow was found, which turned out to be exploitable at least on some platforms) can be tricked into not logging all information. Please see the attached URL for an analysis of the problem.
I don't consider this a problem since even if the long word was passed to syslog() it would get truncated anyway (since syslog has its own line length limits). Please note that long commands are still logged, it is only long *words* (> ~900 characters) that are truncated. In normal (non-attack) usage this simply does not occur.