OL6-00-000206 - The telnet-server package must not be installed.

Information

Removing the 'telnet-server' package decreases the risk of the unencrypted telnet service's accidental (or intentional) activation.

Mitigation: If the telnet-server package is configured to only allow encrypted sessions, such as with Kerberos or the use of encrypted network tunnels, the risk of exposing sensitive information is mitigated.

Solution

The 'telnet-server' package can be uninstalled with the following command:

# yum erase telnet-server

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|I, CCI|CCI-000381, Rule-ID|SV-208913r793699_rule, STIG-ID|OL6-00-000206, STIG-Legacy|SV-64757, STIG-Legacy|V-50551, Vuln-ID|V-208913

Plugin: Unix

Control ID: 17d785be7d9fa972d7541041869b38b68be224fa0c3e95a8e4989214c892e347