Red Hat Bugzilla – Bug 452390
PATH and EXECVE audit records contain bogus newlines
Last modified: 2015-05-04 21:15:12 EDT
Description of problem:
PATH records, as output by the kernel, contain a newline after the flags fields,
which is in the middle of the record.
EXECVE records contain a newline after every argument.
auditd seems to hide this, but they're there nevertheless. If you're not using
auditd, you need to work round them.
I've attached a patch which I think would fix them. However, I'm not able to
test the patch *at all* right now (even for compilation).
Version-Release number of selected component (if applicable):
Created attachment 309983 [details]
Patch to remove bogus newlines in PATH and EXECVE records
Updating PM score.
Committed in 78.28.EL . RPMS are available at http://people.redhat.com/vgoyal/rhel4/
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.