UCF STIG Viewer Logo

The rsh-server package must not be installed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-38591 RHEL-06-000213 SV-50392r1_rule High
Description
The "rsh-server" package provides several obsolete and insecure network services. Removing it decreases the risk of those services' accidental (or intentional) activation.
STIG Date
Red Hat Enterprise Linux 6 Security Technical Implementation Guide 2015-05-26

Details

Check Text ( C-46149r1_chk )
Run the following command to determine if the "rsh-server" package is installed:

# rpm -q rsh-server


If the package is installed, this is a finding.
Fix Text (F-43539r1_fix)
The "rsh-server" package can be uninstalled with the following command:

# yum erase rsh-server