AXBA:2020-990:05

リリース日: 
2020/12/16 Wednesday - 04:03
題名: 
scap-security-guide-0.1.52-2.el7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
N/A
Description: 

The scap-security-guide project provides a guide for configuration of the
system from the final system's security point of view. The guidance is
specified in the Security Content Automation Protocol (SCAP) format and
constitutes a catalog of practical hardening advice, linked to government
requirements where applicable. The project bridges the gap between
generalized policy requirements and specific implementation guidelines.

Bug Fix(es) and Enhancement(s):

* The "DISA STIG for Asianux Server 7" profile in the SCAP Security Guide has been updated to the latest version V3R1. This update adds more coverage and fixes reference problems.

You should use only the current version of this profile because the older versions of this profile are no longer valid. The OVAL checks for several rules have changed, and scans using the V3R1 version will fail for systems that were hardened using older versions of SCAP Security Guide. You can fix the rules automatically by running the remediation with the new version of SCAP Security Guide.

WARNING: Automatic remediation might render the system non-functional. Run the remediation in a test environment first.

The following rules have been changed:

CCE-80224-9:: The default value of this SSHD configuration has changed from "delayed" to "yes". You must now provide a value according to recommendations. Check the rule description for information about fixing this problem or run the remediation to fix it automatically.

CCE-80393-2:: xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon
CCE-80394-0:: xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon
CCE-80391-6:: xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage
CCE-80660-4:: xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles
CCE-80392-4:: xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool
CCE-82362-5:: xccdf_org.ssgproject.content_rule_audit_rules_execution_seunshare
CCE-80398-1:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage
CCE-80404-7:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh
CCE-80410-4:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab
CCE-80397-3:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd
CCE-80403-9:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp
CCE-80411-2:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check
CCE-27437-3:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands
CCE-80395-7:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd
CCE-80406-2:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop
CCE-80407-0:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue
CCE-80408-8:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign
CCE-80402-1:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudoedit
CCE-80401-3:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo
CCE-80400-5:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su
CCE-80405-4:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount
CCE-80396-5:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd
CCE-80399-9:: xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. scap-security-guide-0.1.52-2.el7.src.rpm
    MD5: 6273a838ed968a1276dc523c87d49466
    SHA-256: 61f199a35175c6bcdea214f51fb152e850136832fcac44533744b8503e8a1413
    Size: 6.32 MB

Asianux Server 7 for x86_64
  1. scap-security-guide-0.1.52-2.el7.noarch.rpm
    MD5: 4a1715bc8c5bc59429c9ca5f052ca2b5
    SHA-256: 84c8ef4567feae6e6e73977bc11fc9b216c19994525fb43357651b4cdc8aa14a
    Size: 8.12 MB
  2. scap-security-guide-doc-0.1.52-2.el7.noarch.rpm
    MD5: 946f1792f8d305c46a0febe179abc42e
    SHA-256: 7a1f892d27dd876b3b9e0e53d2e57501e2c2756f13796c9960b810ca818fe263
    Size: 5.16 MB
Copyright© 2007-2015 Asianux. All rights reserved.