Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-4273 | GEN006260 | SV-63947r1_rule | ECLP-1 | Medium |
Description |
---|
Excessive permissions on the "incoming.conf" file may allow unauthorized modification which could lead to Denial-of-Service to authorized users or provide access to unauthorized users. |
STIG | Date |
---|---|
Oracle Linux 5 Security Technical Implementation Guide | 2015-03-26 |
Check Text ( C-52445r1_chk ) |
---|
The file corresponding to "/etc/news/hosts.nntp" is "/etc/news/incoming.conf". Check the permissions for "/etc/news/incoming.conf". # ls -lL /etc/news/incoming.conf If "/etc/news/incoming.conf" has a mode more permissive than 0600, this is a finding. |
Fix Text (F-54515r1_fix) |
---|
Change the mode of the "/etc/news/incoming.conf" file to 0600. # chmod 0600 /etc/news/incoming.conf |