1.2.1.8 Ensure access to /etc/apt/sources.list.d directory is configured

Information

The /etc/apt/sources.list.d directory provides a way to add sources.list entries in separate files.

/etc/apt/sources.list.d directory contains files with repositories to be used by APT. A non-root user should not be able to add or remove files from this directory. Misconfiguring could allow a non-root user to add repositories containing malicious packages.

Solution

Run the following command to set permissions to /etc/apt/sources.list.d Uid and Gid to 0/root and access to 0755 or more restrictive:

# chown root:root /etc/apt/sources.list.d
# chmod u=rwx,g=rx,o=rx /etc/apt/sources.list.d

See Also

https://workbench.cisecurity.org/benchmarks/26891

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 8c131055093d05b8c1239efc22aa26058968e6591684ab86c1a9a7c00442680e