Rule ID
SV-44950r1_rule
Version
V1R12
CCIs
If manual pages are compromised, misleading information could be inserted, causing actions to compromise the system.
Verify all manual page files have no extended ACLs. # ls -lL /usr/share/man /usr/share/man/man* /usr/share/info If the permissions include a '+', the file has an extended ACL this is a finding.
Remove the extended ACL from the file. # setfacl --remove-all /usr/share/man/* /usr/share/man/man* /usr/share/info/*