GEN001310 - All library files must not have extended ACLs - '/usr/lib/*'

Information

Unauthorized access could destroy the integrity of the library files.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /usr/lib/* /lib/*

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-001499, Rule-ID|SV-64531r2_rule, STIG-ID|GEN001310, Vuln-ID|V-22317

Plugin: Unix

Control ID: 0a0995f1852ac131beaf49c53ff00e12595dd122fc11cf4da37201d844c575dd