STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide

V-793

CAT II (Medium)

Library files must have mode 0755 or less permissive.

Rule ID

SV-44951r1_rule

STIG

SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide

Version

V1R12

CCIs

CCI-001499

Discussion

Unauthorized access could destroy the integrity of the library files.

Check Content

Check the mode of library files.

Procedure:
# DIRS="/usr/lib /usr/lib64 /lib /lib64";for DIR in $DIRS;do find $DIR -type f -perm +022 -exec stat -c %a:%n {} \;;done

This will return the octal permissions and name of all group or world writable files.
If any file listed is world or group writable (either or both of the 2 lowest order digits contain a 2, 3 or 6), this is a finding.

Fix Text

Change the mode of library files to 0755 or less permissive.

Procedure (example):
# chmod go-w </path/to/library-file>

Note: Library files should have an extension of ".a" or a ".so" extension, possibly followed by a version number.