UCF STIG Viewer Logo

Audio devices must have mode 0660 or less permissive.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1048 GEN002320 SV-27241r1_rule ECLP-1 Medium
Description
Globally accessible audio and video devices have proven to be security hazards. There is software that can activate system microphones and video devices connected to user workstations and/or X terminals. Once the microphone has been activated, it is possible to eavesdrop on otherwise private conversations without the victim being aware of it. This action effectively changes the user's microphone to a bugging device.
STIG Date
SOLARIS 9 X86 SECURITY TECHNICAL IMPLEMENTATION GUIDE 2015-10-01

Details

Check Text ( C-28265r1_chk )
Check the mode of audio devices.
# ls -lL /dev/audio
If the mode of audio devices are more permissive than 0660, this is a finding.
Fix Text (F-34401r1_fix)
Change the mode of the audio device.
# chmod -R 0660 /dev/audio