Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-227542 | GEN000000-SOL00240 | SV-227542r603266_rule | Medium |
Description |
---|
If the userlist file is not owned by root, then an unauthorized user can modify the file and enter an unauthorized user. |
STIG | Date |
---|---|
Solaris 10 X86 Security Technical Implementation Guide | 2020-12-04 |
Check Text ( C-29704r488159_chk ) |
---|
If ASET is not used on the system, this is not applicable. Check the ownership of the /usr/aset/userlist file. # ls -lL /usr/aset/userlist If the owner of the file is not root, this is a finding. |
Fix Text (F-29692r488160_fix) |
---|
Use the chmod command to change the owner of the /usr/aset/userlist file. # chown root /usr/aset/userlist |