UCF STIG Viewer Logo

The portmap or rpcbind service must not be installed unless needed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22430 GEN003815 SV-63997r1_rule Medium
Description
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
STIG Date
Oracle Linux 5 Security Technical Implementation Guide 2020-02-25

Details

Check Text ( C-52591r1_chk )
Check if the portmap package is installed.
# rpm -qa | grep portmap
If a package is found, this is a finding.
Fix Text (F-54705r1_fix)
Remove the portmap package.
# rpm -e portmap
or
# yum remove portmap