2.3.3 Ensure talk client is not installed

Information

The talk software makes it possible for users to send and receive messages across systems through a terminal session. The talk client, which allows initialization of talk sessions, is installed by default.
Rationale:
The software presents a security risk as it uses unencrypted protocols for communication.

Solution

Run the following command to uninstall talk:
apt-get remove talk

See Also

https://workbench.cisecurity.org/files/2242

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|2.6

Plugin: Unix

Control ID: a90dd40ea84457cc964875375b41828d616bb6e56dca901ee7c8521ff6014b2b