GEN000950 - The root account's list of preloaded libraries must be empty.

Information

The library preload list environment variable contains a list of libraries for the dynamic linker to load before loading the libraries required by the binary. If this list contains paths to libraries relative to the current working directory, unintended libraries may be preloaded. This variable is formatted as a space-separated list of libraries. Paths starting with (/) are absolute paths.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Edit the root user's initialization files and remove any definition of LDR_PRELOAD.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-38772r1_rule, STIG-ID|GEN000950, Vuln-ID|V-22311

Plugin: Unix

Control ID: 17ffc22d9c17144f491412a2edac86304252c0ea34e6f3b3796f51c5f1ae46cc