UCF STIG Viewer Logo

The portmap or rpcbind service must not be installed unless needed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-227821 GEN003815 SV-227821r603266_rule Medium
Description
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
STIG Date
Solaris 10 X86 Security Technical Implementation Guide 2022-09-07

Details

Check Text ( C-29983r489823_chk )
If the system needs the portmap service to operate, this is not applicable. The rpcbind program is part of a core Solaris package and cannot be removed. Verify the permissions on the rpcbind file.
# ls -lL /usr/sbin/rpcbind
If the rpcbind service is not required and the rpcbind file has non-zero permissions, this is a finding.
Fix Text (F-29971r489824_fix)
Remove all permissions from the rpcbind file.

Procedure:
# chmod 0000 /usr/sbin/rpcbind