Korean
<< Back
VID 14130
Severity 30
Port 22
Protocol TCP
Class LSC
Detailed Description The host system's /etc/profile file's permission or owner is unsafe. /etc/profile is a file that defines the script to be applied when the user logs in.
If this file is exposed, serious security problems can occur. So normal users need to be prohibited from accessing this file.

* Platforms Affected:
UNIX, Linux
Recommendation Reset permissions of the file lower than 755 as the following
chmod 755 /etc/profile

if the owner of the file is not root, change the owner
chown root /etc/profile
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)