GEN008820 - The system package management tool must not automatically obtain updates.

Information

System package management tools can obtain a list of updates and patches from a package repository and make this information available to the SA for review and action. Using a package repository outside of the organization's control presents a risk of malicious packages being introduced.

Solution

Disable the yum service.
# chkconfig yum-updatesd off ; service yum-updatesd stop

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(2), CAT|III, CCI|CCI-001233, Group-ID|V-22589, Rule-ID|SV-26992r1_rule, STIG-ID|GEN008820, Vuln-ID|V-22589

Plugin: Unix

Control ID: 4b7cf5bd5a3c8730c2a2d627591f307ef5b68ff21fb75ac9edbbcded2fd44cf2