GEN004370 - The aliases file must be group-owned by sys, bin, or system.

Information

If the alias file is not group-owned by a system group, an unauthorized user may modify the file to add aliases to run malicious code or redirect e-mail.

Solution

Change the group owner of the /etc/mail/aliases file.

Procedure:
# chgrp system /etc/mail/aliases

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22438, Rule-ID|SV-40683r1_rule, STIG-ID|GEN004370, Vuln-ID|V-22438

Plugin: Unix

Control ID: 96609c50f2ba6c1ae92df760e924ff42f64493f7caf6e90cf14255a13b2b8198