Bugzilla – Bug 941922
VUL-1: CVE-2015-5186: audit: log terminal emulator escape sequences handling
Last modified: 2019-05-07 14:55:21 UTC
rh#1251621 Steve Grubb of Red Hat reports: When auditing the filesystem the names of files are logged. These filenames can contain escape sequences, when viewed using the ausearch programs "-i" option for example this can result in the escape sequences being processed unsafely by the terminal program being used to view the data. Upstream commit: https://fedorahosted.org/audit/changeset/1122 CVE-2015-5186 was assigned to this issue. References: https://bugzilla.redhat.com/show_bug.cgi?id=1251621 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5186 http://seclists.org/oss-sec/2015/q3/354 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5186
bugbot adjusting priority
Sorry, forgot to submit this from branch :( sr 329224
SUSE-SU-2019:0563-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1042781,1085003,1125535,941922 CVE References: CVE-2015-5186 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): audit-2.8.1-10.3.2 SUSE Linux Enterprise Server 12-SP4 (src): audit-2.8.1-10.3.2, audit-secondary-2.8.1-10.3.2 SUSE Linux Enterprise Desktop 12-SP4 (src): audit-2.8.1-10.3.2, audit-secondary-2.8.1-10.3.2
SUSE-SU-2019:1166-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1042781,1085003,1125535,941922 CVE References: CVE-2015-5186 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): audit-2.8.1-8.3.1 SUSE Linux Enterprise Server 12-SP3 (src): audit-2.8.1-8.3.1, audit-secondary-2.8.1-8.3.3 SUSE Linux Enterprise Desktop 12-SP3 (src): audit-2.8.1-8.3.1, audit-secondary-2.8.1-8.3.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.