GEN002340 - Audio devices must be owned by root.

Information

Audio and video devices that are globally accessible have proven to be another security hazard. There is software that can activate system microphones and video devices connected to user workstations and/or X terminals. Once the microphone has been activated, it is possible to eavesdrop on otherwise private conversations without the victim being aware of it. This action effectively changes the user's microphone to a bugging device.

Solution

Change the owner of the audio device.
# chown root <audio device>

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-27248r1_rule, STIG-ID|GEN002340, Vuln-ID|V-1049

Plugin: Unix

Control ID: 9e3485c14619a5b624bf7d21281698dfb973e45cfe5323f64a0c8ed468f21254