VID |
14141 |
Severity |
30 |
Port |
22 |
Protocol |
TCP |
Class |
LSC |
Detailed Description |
The host system's /etc/security/failedlogin file's permission or owner is unsafe. /etc/security/failedlogin is a log file that is logged if an attempt is made to log in to the system but it fails. If this file is exposed, serious security problems can occur. So normal users need to be prohibited from accessing this file.
* Platforms Affected: UNIX, Linux |
Recommendation |
Reset permissions of the file lower than 600 as the following chmod 600 /etc/security/failedlogin
if the owner of the file is not root, change the owner chown root /etc/security/failedlogin |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|