Recommended update for audit

SUSE Recommended Update: Recommended update for audit
Announcement ID: SUSE-RU-2013:0329-1
Rating: low
References: #792713
Affected Products:
  • SUSE Linux Enterprise Software Development Kit 11 SP2
  • SUSE Linux Enterprise Server 11 SP2 for VMware
  • SUSE Linux Enterprise Server 11 SP2
  • SUSE Linux Enterprise Desktop 11 SP2

  • An update that has one recommended fix can now be installed. It includes one version update.

    Description:


    The set of tools for Kernel Auditing (audit) has been
    updated to version 1.8. The update brings many fixes and
    enhancements, including:

    * Add definitions for crypto events
    * Add tcp_wrappers configuration option to auditd
    * Add interpretations for epoll_ctl, lseek, and
    sigaction to libauparse
    * Add aulast, a program that prints a list of the last
    logged in users
    * Add system boot, shutdown, and run level change events
    * Add max_restarts to audispd.conf to limit plugin
    restarts
    * Add new kernel capability event record types
    * Add support in ausearch and aureport for TTY data
    * Add new aureport option for TTY keystroke report
    * Interpret TTY audit data in auparse
    * Allow aulastlog to read input from standard input
    * Allow ausearch and aureport to specify multiple node
    names
    * Allow auditd log rotation via SIGUSR1 when NOLOG log
    format option is enabled
    * Allow the keyword "any" for local_port in
    audisp-remote
    * Send AUDIT_RMW_TYPE_ENDING messages to clients when
    auditd shuts down
    * Fix ausearch and aureport to handle out of order
    events
    * Fix problem with negative UIDs in audit rules on
    32bit systems
    * Fix bug interpreting i386 logs on x86_64 machines
    * Fix uninitialized variable in aureport that could
    cause a segmentation fault
    * Improve performance of ausearch and aureport.

    The format of messages printed by the tools or logs
    generated might have changed to improve readability or
    include more information. For a comprehensive list of
    changes please refer to the package change log.

    Patch Instructions:

    To install this SUSE Recommended Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Software Development Kit 11 SP2:
      zypper in -t patch sdksp2-audit-18-7264
    • SUSE Linux Enterprise Server 11 SP2 for VMware:
      zypper in -t patch slessp2-audit-18-7264
    • SUSE Linux Enterprise Server 11 SP2:
      zypper in -t patch slessp2-audit-18-7264
    • SUSE Linux Enterprise Desktop 11 SP2:
      zypper in -t patch sledsp2-audit-18-7264

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.8]:
    • audit-devel-1.8-0.28.1
    • SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 x86_64) [New Version: 1.8]:
    • audit-libs-python-1.8-0.28.1
    • SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 1.8]:
    • audit-1.8-0.28.1
    • audit-audispd-plugins-1.8-0.28.1
    • audit-libs-1.8-0.28.1
    • audit-libs-python-1.8-0.28.1
    • SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 1.8]:
    • audit-libs-32bit-1.8-0.28.1
    • SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.8]:
    • audit-1.8-0.28.1
    • audit-audispd-plugins-1.8-0.28.1
    • audit-libs-1.8-0.28.1
    • audit-libs-python-1.8-0.28.1
    • SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 1.8]:
    • audit-libs-32bit-1.8-0.28.1
    • SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 1.8]:
    • audit-libs-x86-1.8-0.28.1
    • SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 1.8]:
    • audit-1.8-0.28.1
    • audit-libs-1.8-0.28.1
    • SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 1.8]:
    • audit-libs-32bit-1.8-0.28.1

    References:

    • https://bugzilla.novell.com/792713
    • http://download.suse.com/patch/finder/?keywords=ef44c3798aa618ace55800923eca3069