Check: GEN001290
Solaris 10 X86 STIG:
GEN001290
(in versions v2 r4 through v1 r17)
Title
All manual page files must not have extended ACLs. (Cat III impact)
Discussion
If manual pages are compromised, misleading information could be inserted, causing actions that may compromise the system.
Check Content
Verify all manual page files have no extended ACLs. Check environment variable $MANPATH for full list of manpage locations. # echo $MANPATH Check for ACLs, note only a partial list is presented below. # ls -lLR /usr/share/man /usr/sfw/man /usr/sfw/share/man If the permissions include a "+", the file has an extended ACL and this is a finding.
Fix Text
Remove the extended ACL from the file. # chmod A- [file with extended ACL]
Additional Identifiers
Rule ID: SV-227622r603266_rule
Vulnerability ID: V-227622
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |