5.1.5 Ensure talk client is not installed

Information

The talk software makes it possible for users to send and receive messages across systems
through a terminal session. The talk client (allows initialization of talk sessions) is
installed by default.

*Rationale*

The software presents a security risk as it uses unencrypted protocols for communication.

Solution

Uninstall the talk package-# apt-get purge talk

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), 800-53|CM-7b.

Plugin: Unix

Control ID: 6551c2bb236ac95f3bacf981d683d29257f9695abfe1f4a8ea4b0babdde4a693