STIGQter STIGQter: STIG Summary: Oracle Linux 5 Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 26 Oct 2018: At jobs must not set the umask to a value less restrictive than 077.

DISA Rule

SV-64409r1_rule

Vulnerability Number

V-4366

Group Title

GEN003440

Rule Version

GEN003440

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit "at" jobs or referenced scripts to remove "umask" commands that set umask to a value less restrictive than 077.

Check Contents

Determine what "at" jobs exist on the system.
Procedure:
# ls /var/spool/at

If there are no "at" jobs present, this is not applicable.

Determine if any of the "at" jobs or any scripts referenced execute the "umask" command. Check for any umask setting more permissive than 077.

# grep umask <at job or referenced script>

If any "at" job or referenced script sets umask to a value more permissive than 077, this is a finding.

Vulnerability Number

V-4366

Documentable

True

Rule Version

GEN003440

Severity Override Guidance

Determine what "at" jobs exist on the system.
Procedure:
# ls /var/spool/at

If there are no "at" jobs present, this is not applicable.

Determine if any of the "at" jobs or any scripts referenced execute the "umask" command. Check for any umask setting more permissive than 077.

# grep umask <at job or referenced script>

If any "at" job or referenced script sets umask to a value more permissive than 077, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

2207

Comments