GEN004370 - The aliases file must be group-owned by root, sys, smmsp, or bin.

Information

If the alias file is not group-owned by root or a system group, an unauthorized user may modify the file to add aliases to run malicious code or redirect email.

Solution

Change the group owner of the /etc/mail/aliases files.

Procedure:
# chgrp bin /etc/mail/aliases
# chgrp smmsp /etc/mail/aliases.db

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-220045r858545_rule, STIG-ID|GEN004370, STIG-Legacy|SV-37458, STIG-Legacy|V-22438, Vuln-ID|V-220045

Plugin: Unix

Control ID: e399cd85291fb118e108a3a2204acbcc038f688722c1a35f934f2ee16f024c88