The Automatic Bug Reporting Tool (abrtd) service must not be running.
Mishandling crash data could expose sensitive information about vulnerabilities in software executing on the local machine, as well as sensitive information from within a process's address space or registers.
Run the following command to verify "abrtd" is disabled through current runtime configuration:
# service abrtd status
If the service is disabled the command will return the following output:
abrtd is stopped
If the service is running, this is a finding.
Fix Text (F-19494r377061_fix)
The Automatic Bug Reporting Tool ("abrtd") daemon collects and reports crash data when an application crash is detected. Using a variety of plugins, abrtd can email crash reports to system administrators, log crash reports to files, or forward crash reports to a centralized issue tracking system such as RHTSupport. The "abrtd" service can be disabled with the following commands: