Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-821 | GEN003720 | SV-45757r1_rule | ECLP-1 | Medium |
Description |
---|
Failure to give ownership of sensitive files or utilities to root provides the designated owner and unauthorized users with the potential to access sensitive information or change the system configuration possibly weakening the system's security posture. |
STIG | Date |
---|---|
SUSE Linux Enterprise Server v11 for System z | 2015-01-26 |
Check Text ( C-43110r1_chk ) |
---|
Check the owner of the xinetd configuration files. Procedure: # ls -lL /etc/xinetd.conf # ls -laL /etc/xinetd.d This is a finding if any of the above files or directories are not owned by root or bin. |
Fix Text (F-39156r1_fix) |
---|
Change the owner of the xinetd configuration files. # chown root /etc/xinetd.conf /etc/xinetd.d/* |