1.2.1.9 Ensure access to files in /etc/apt/sources.list.d are configured

Information

Files in the /etc/apt/sources.list.d directory provides a way to add sources.list entries in separate files.

Files in the /etc/apt/sources.list.d directory contain information about repositories to be used by APT. A non-root user should not be able to add or remove files from this directory. Misconfiguring could allow a non-root user to add repositories containing malicious packages.

Solution

Run the following command to set permissions to /etc/apt/sources.list.d directory Uid and Gid to 0/root and access to 0644 or more restrictive:

# chown root:root /etc/apt/sources.list.d/*
# chmod u-x,go-wx /etc/apt/sources.list.d/*

See Also

https://workbench.cisecurity.org/benchmarks/24932

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: ac0265f76a8908880c67316a2058a8ec4cd2109528b990a96529e13bef5d141e