Check: RHEL-06-000222
Red Hat Enterprise Linux 6 STIG:
RHEL-06-000222
(in versions v2 r2 through v1 r21)
Title
The tftp-server package must not be installed unless required. (Cat II impact)
Discussion
Removing the "tftp-server" package decreases the risk of the accidental (or intentional) activation of tftp services.
Check Content
Run the following command to determine if the "tftp-server" package is installed: # rpm -q tftp-server If the package is installed and not documented and approved by the ISSO, this is a finding.
Fix Text
The "tftp-server" package can be removed with the following command: # yum erase tftp-server
Additional Identifiers
Rule ID: SV-217991r603264_rule
Vulnerability ID: V-217991
Group Title: SRG-OS-000095
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-7 |
Least Functionality |