GEN004360 - The alias file must be owned by root.

Information

If the alias file is not owned by root, an unauthorized user may modify the file to add aliases to run malicious code or redirect email.

Solution

Change the owner of the /etc/mail/aliases file (or equivalent, such as /usr/lib/aliases) to root.
Procedure:
# chown root /etc/mail/aliases

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-40836r1_rule, STIG-ID|GEN004360, Vuln-ID|V-831

Plugin: Unix

Control ID: c849aa078c7fddd3c07f5437a769794a77d1dfdbe66b0e4d9304d325046168ed