GEN008820 - The system package management tool must not automatically obtain updates.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

System package management tools can obtain a list of updates and patches from a package repository and make this information available to the SA for review and action. Using a package repository outside of the organization's control presents a risk of malicious packages being introduced.

Solution

Disable the yum service.
# chkconfig yum-updatesd off ; service yum-updatesd stop

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CCI|CCI-001233, CSCv6|9.1, Rule-ID|SV-63025r1_rule, STIG-ID|GEN008820, Vuln-ID|V-22589

Plugin: Unix

Control ID: 684d128ee16307710a74935630e9f71b8bfbe70b20e2ca7cc0625eac1f0b317e