GEN003980 - The traceroute command must be group-owned by sys, bin, or system.

Information

If the group owner of the traceroute command has not been set to a system group, unauthorized users could have access to the command and use it to gain information regarding a network's topology inside of the firewall. This information may allow an attacker to determine trusted routers and other network information possibly leading to system and network compromise.

Solution

Change the group owner of the traceroute command to sys, bin, or system.
Procedure:
# chgrp system /usr/bin/traceroute

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-28397r1_rule, STIG-ID|GEN003980, Vuln-ID|V-4370

Plugin: Unix

Control ID: 871d1f55583bc078848371fdde623c647dfbb68fcf889ee572ada0d79b24634f