Rule ID
SV-45673r2_rule
Version
V1R12
CCIs
If the group of the "atjobs" directory is not root, bin, daemon, sys, or at, unauthorized users could be allowed to view or edit files containing sensitive information within the directory.
Check the group ownership of the directory. Procedure: # ls -ld /var/spool/atjobs If the file is not group-owned by root, bin, daemon, sys, or at, this is a finding.
Change the group ownership of the directory to root, bin, sys, daemon or cron. Procedure: # chgrp <root|bin|daemon|sys|at> <"atjobs" directory>