Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26793
http://www.securityfocus.com/bid/19795
http://tor.eff.org/cvs/tor/ChangeLog
http://security.gentoo.org/glsa/glsa-200606-04.xml