VID |
14146 |
Severity |
30 |
Port |
22 |
Protocol |
TCP |
Class |
LSC |
Detailed Description |
The host system's /etc/security/passwd file's permission or owner is unsafe. /etc/security/passwd contains the encrypted password and the user's updated information. If this file is exposed, serious security problems can occur. So normal users need to be prohibited from accessing this file.
* Platforms Affected: UNIX, Linux |
Recommendation |
Reset permissions of the file lower than 400 as the following chmod 400 /etc/security/passwd
if the owner of the file is not root, change the owner chown root /etc/security/passwd |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|