GEN004360 - The alias file must be owned by root.

Information

If the alias file is not owned by root, an unauthorized user may modify the file to add aliases to run malicious code or redirect email.

Solution

Change the owner of the /etc/mail/aliases file (or equivalent, such as /usr/lib/aliases) to root.

Procedure:
# chown root /etc/mail/aliases

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4(8), CAT|II, CCI|CCI-002195, Rule-ID|SV-227837r858555_rule, STIG-ID|GEN004360, STIG-Legacy|SV-40493, STIG-Legacy|V-831, Vuln-ID|V-227837

Plugin: Unix

Control ID: 7f8617249014830a1edf5ad8170844fcb21a28e57fa6ea0180daf59b24079f9c