Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-956 | GEN000000-SOL00240 | SV-956r2_rule | ECLP-1 | Medium |
Description |
---|
If the userlist file is not owned by root, then an unauthorized user can modify the file and enter an unauthorized user. |
STIG | Date |
---|---|
SOLARIS 10 SPARC SECURITY TECHNICAL IMPLEMENTATION GUIDE | 2016-06-22 |
Check Text ( C-28804r1_chk ) |
---|
If ASET is not used on the system, this is not applicable. Check the ownership of the /usr/aset/userlist file. # ls -lL /usr/aset/userlist If the owner of the file is not root, this is a finding. |
Fix Text (F-1110r2_fix) |
---|
Use the chmod command to change the owner of the /usr/aset/userlist file. # chown root /usr/aset/userlist |