UCF STIG Viewer Logo

The portmap or rpcbind service must not be installed unless needed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-226916 GEN003815 SV-226916r603265_rule Medium
Description
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
STIG Date
Solaris 10 SPARC Security Technical Implementation Guide 2020-12-04

Details

Check Text ( C-29078r485038_chk )
If the system needs the portmap service to operate, this is not applicable. The rpcbind program is part of a core Solaris package and cannot be removed. Verify the permissions on the rpcbind file.
# ls -lL /usr/sbin/rpcbind
If the rpcbind service is not required and the rpcbind file has non-zero permissions, this is a finding.
Fix Text (F-29066r485039_fix)
Remove all permissions from the rpcbind file.

Procedure:
# chmod 0000 /usr/sbin/rpcbind