5.1.4 Check Library folder for world writable files

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Software sometimes insists on being installed in the '/Library' Directory and have inappropriate world writable permissions.

Rationale:

Folders in '/Library' should not be world writable. The audit check excludes the '/Library/Caches' folder where the sticky bit is set.

Solution

Change permissions so that 'Others' can only execute. (Example Below)

sudo chmod -R o-w /Bad/Directory

See Also

https://workbench.cisecurity.org/files/2112

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 222d80a1c1928824b6ff9b391258f90ec0c4f0d9de5b17db862d3cf1c59a69f6