GEN003360 - The at daemon must not execute group-writable or world-writable programs - at daemon must not execute group-writable or world-writable programs.

Information

If the 'at' facility executes world-writable or group-writable programs, it is possible for the programs to be accidentally or maliciously changed or replaced without the owner's intent or knowledge. This would cause a system security breach.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove group-write and world-write permissions from files executed by at jobs.

Procedure:
# chmod go-w <file>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-5(6), CAT|II, CCI|CCI-000225, CCI|CCI-001499, Rule-ID|SV-218460r603259_rule, STIG-ID|GEN003360, STIG-Legacy|SV-64469, STIG-Legacy|V-988, Vuln-ID|V-218460

Plugin: Unix

Control ID: 0c71e080b7397b8cb1d89e7e2361a8d81f0822545952dae5a3b30d13b17f5479