Bug 1251621 - (CVE-2015-5186) CVE-2015-5186 Audit: log terminal emulator escape sequences handling
CVE-2015-5186 Audit: log terminal emulator escape sequences handling
Status: ASSIGNED
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150813,repor...
: Reopened, Security
Depends On: 1400791
Blocks: 1251622 1386080
  Show dependency treegraph
 
Reported: 2015-08-07 19:54 EDT by Kurt Seifried
Modified: 2016-12-30 11:02 EST (History)
20 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-28 03:57:30 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Patch fixing unescaped control characters (27.04 KB, patch)
2015-08-10 19:39 EDT, Steve Grubb
no flags Details | Diff

  None (edit)
Description Kurt Seifried 2015-08-07 19:54:44 EDT
Steve Grubb of Red Hat reports:

When auditing the filesystem the names of files are logged. These filenames 
can contain escape sequences, when viewed using the ausearch programs "-i" 
option for example this can result in the escape sequences being processed 
unsafely by the terminal program being used to view the data.
Comment 1 Steve Grubb 2015-08-10 19:39:56 EDT
Created attachment 1061284 [details]
Patch fixing unescaped control characters

This patch will be applied upstream. Please share with other distributions. The older the audit package, the more likely they will have problems back porting.
Comment 2 Kurt Seifried 2015-08-13 16:58:44 EDT
This has been corrected upstream with the following commit:

https://fedorahosted.org/audit/changeset/1122
Comment 4 Kurt Seifried 2015-08-26 10:35:00 EDT
Acknowledgement:

This issue was discovered by Steve Grubb of Red Hat.

Note You need to log in before you can comment on or make changes to this bug.