Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Security Update: 2019:1166-1 - Moderate Audit Vulnerability Fix

suse
Calendar Grey May 7, 2019
Dist Suse Esm H88
SUSE Security Patch for Audit: addresses a medium-severity concern with suggested resolutions provided.
An update that solves one vulnerability and has three fixes is now available

Summary

This update for audit fixes the following issues: Audit on SUSE Linux Enterprise 12 SP3 was updated to 2.8.1 to bring new features and bugfixes. (bsc#1125535 FATE#326346) * Many features were added to auparse_normalize * cli option added to auditd and audispd for setting config dir * In auditd, restore the umask after creating a log file * Option added to auditd for skipping email verification The full changelog can be found here: https://people.redhat.com/sgrubb/audit/ChangeLog - Change openldap dependency to client only (bsc#1085003) Minor security issue fixed: - CVE-2015-5186: Audit: log terminal emulator escape sequences handling (bsc#941922) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1042781 #1085003 #1125535 #941922

Cross- CVE-2015-5186

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2015-5186.html

https://bugzilla.suse.com/1042781

https://bugzilla.suse.com/1085003

https://bugzilla.suse.com/1125535

https://bugzilla.suse.com/941922

Announcement ID: SUSE-SU-2019:1166-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here