RHEL-06-000528 - The noexec option must be added to the /tmp partition.

Information

Allowing users to execute binaries from world-writable directories such as '/tmp' should never be necessary in normal operation and can expose the system to potential compromise.

Solution

The 'noexec' mount option can be used to prevent binaries from being executed out of '/tmp'. Add the 'noexec' option to the fourth column of '/etc/fstab' for the line which controls mounting of '/tmp'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCE|CCE-14927-8, CCI|CCI-000381, Rule-ID|SV-218106r603264_rule, STIG-ID|RHEL-06-000528, STIG-Legacy|SV-71919, STIG-Legacy|V-57569, Vuln-ID|V-218106

Plugin: Unix

Control ID: 418539cbd81050b986f9796091e9bb1f811e2322c38da8e110e6124d7c1a7666