GEN001310 M6 - All library files must not have extended ACLs - '/System/Library/Frameworks'

Information

Unauthorized access could destroy the integrity of the library files.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -RN /System/Library/Frameworks /Library/Frameworks /usr/lib /usr/local/lib

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-001499, Rule-ID|SV-38075r1_rule, STIG-ID|GEN001310-M6, Vuln-ID|V-22317

Plugin: Unix

Control ID: 042fbca883c77b5c7bf6f18fd56d1084658df65383cb4ccfabc45f693fcbde25