[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-95007-1

Platform: cpe:/o:ubuntu:ubuntu_linux:20.04, cpe:/o:ubuntu:ubuntu_linux:22.04, cpe:/o:ubuntu:ubuntu_linux:23.04Date: (C)2020-10-15   (M)2023-09-01



The /etc/passwd file contains a list of all the valid userIDs defined in the system, but not the passwords. The command below sets the owner and group of the file to root. UID - User Identifier is a number assigned by Linux to each user on the system. This number is used to identify the user to the system and to determine which system resources the user can access. UIDs are stored in the /etc/passwd file: Rationale: The /etc/passwd file needs to be protected from unauthorized changes by non-priliveged users, but needs to be readable as this information is used with many non-privileged programs. Fix: If the user and group ownership of the /etc/passwd file are incorrect, run the following command to correct them: # /bin/chown root:root /etc/passwd


Parameter:

[UID of ROOT, GID of ROOT]


Technical Mechanism:

If the user and group ownership of the /etc/passwd file are incorrect, run the following command to correct them: # /bin/chown root:root /etc/passwd

CCSS Severity:CCSS Metrics:
CCSS Score : 8.4Attack Vector: LOCAL
Exploit Score: 2.5Attack Complexity: LOW
Impact Score: 5.9Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:85086
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:65966
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:92360


OVAL    3
oval:org.secpod.oval:def:85086
oval:org.secpod.oval:def:65966
oval:org.secpod.oval:def:92360
XCCDF    6
xccdf_org.secpod_benchmark_SecPod_Ubuntu_23.04
xccdf_org.secpod_benchmark_SecPod_Ubuntu_22.04
xccdf_org.secpod_benchmark_SecPod_Ubuntu_20.04
xccdf_org.secpod_benchmark_general_Ubuntu_23.04
...

© SecPod Technologies