6.1 Suspicious UDFs

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This will help prevent an attacker from executing arbitrary code. This option prevents attaching arbitrary shared library functions as user-defined functions by checking for at least one corresponding method named _init, _deinit, _reset, _clear, or _add.

Solution

Avoid using the --allow-suspicious-udfs parameter

See Also

https://workbench.cisecurity.org/files/1613

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2)

Plugin: Unix

Control ID: 6cc9d61fc2d9a1b08f8faedac9f7062ab675c1912849310a1a11e1a9568d5479