GEN005100 - The TFTP daemon must have mode 0755 or less permissive.

Information

If TFTP runs with the setuid or setgid bit set, it may be able to write to any file or directory and may seriously impair system integrity, confidentiality, and availability.

Solution

Change the mode of the TFTP daemon.

Procedure:
# chmod 0755 <in.tftpd binary>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|I, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218567r603259_rule, STIG-ID|GEN005100, STIG-Legacy|SV-63163, STIG-Legacy|V-848, Vuln-ID|V-218567

Plugin: Unix

Control ID: fbc43237d1dc58e8893c18b33f24c74269fd4e140d8b435f92b44f840df94639