Korean
<< Back
VID 14136
Severity 30
Port 22
Protocol TCP
Class LSC
Detailed Description The host system's Major backup file's permission or owner is unsafe. Major backup files include /etc/passwd*, /etc/xinetd.conf*, /etc/services*, /etc/hosts*, /var/adm/wtmp*, /var/adm/btmp* /var/adm/sulog*, etc.
If these files are exposed, serious security problems can occur. So normal users need to be prohibited from accessing this file.

* Platforms Affected:
UNIX, Linux
Recommendation Reset permissions of the file lower than 600 as the following
chmod 600 /etc/passwd.old
chmod 600 /var/adm/wtmp.180523

if the owner of the file is not root, change the owner
chown root /etc/passwd.old
chown root /var/adm/wtmp.180523
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)