VID |
14136 |
Severity |
30 |
Port |
22 |
Protocol |
TCP |
Class |
LSC |
Detailed Description |
The host system's Major backup file's permission or owner is unsafe. Major backup files include /etc/passwd*, /etc/xinetd.conf*, /etc/services*, /etc/hosts*, /var/adm/wtmp*, /var/adm/btmp* /var/adm/sulog*, etc. If these files are exposed, serious security problems can occur. So normal users need to be prohibited from accessing this file.
* Platforms Affected: UNIX, Linux |
Recommendation |
Reset permissions of the file lower than 600 as the following chmod 600 /etc/passwd.old chmod 600 /var/adm/wtmp.180523
if the owner of the file is not root, change the owner chown root /etc/passwd.old chown root /var/adm/wtmp.180523 |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|