GEN002320 - Audio devices must have mode 0664 or less permissive - '/dev/audio*'

Information

Audio and video devices that are globally accessible have proven to be another security hazard. There is software that can activate system microphones and video devices connected to user workstations and/or X terminals. Once the microphone has been activated, it is possible to eavesdrop on otherwise private conversations without the victim being aware of it. This action effectively changes the user's microphone into a bugging device.

Solution

Change the mode of audio devices.
# chmod 0660 <audio device>

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-1048, Rule-ID|SV-37566r1_rule, STIG-ID|GEN002320, Vuln-ID|V-1048

Plugin: Unix

Control ID: a31d31611a65f35239ebd38ec193e055d97dc11a3054b9d96ea483471cc8a5c2