GEN002280 - Device files and directories must only be writable by users with a system account or as configured by the vendor.

Information

System device files in writable directories could be modified, removed, or used by an unprivileged user to control system hardware.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove the world-writable permission from the device file(s).

Procedure:
# chmod o-w <device file>

Document all changes.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-924, Rule-ID|SV-37553r3_rule, STIG-ID|GEN002280, Vuln-ID|V-924

Plugin: Unix

Control ID: c246540fd18174f4f3af821eea2c992d5118bce890126d70e2b76e3fc6b061f8