File tree Expand file tree Collapse file tree 1 file changed +13
-3
lines changed Expand file tree Collapse file tree 1 file changed +13
-3
lines changed Original file line number Diff line number Diff line change 317
317
end
318
318
end
319
319
320
- control 'sysctl-31 ' do
320
+ control 'sysctl-31a ' do
321
321
impact 1.0
322
- title 'Secure Core Dumps'
323
- desc 'Ensure that core dumps can never be made by setuid programs or with fully qualified path '
322
+ title 'Secure Core Dumps - dump settings '
323
+ desc 'Ensure that core dumps can never be made by setuid programs'
324
324
325
325
describe kernel_parameter ( 'fs.suid_dumpable' ) do
326
326
its ( :value ) { should cmp ( /(0|2)/ ) }
327
327
end
328
+ end
329
+
330
+ control 'sysctl-31b' do
331
+ impact 1.0
332
+ title 'Secure Core Dumps - dump path'
333
+ desc 'Ensure that core dumps are done with fully qualified path'
334
+ only_if do
335
+ kernel_parameter ( 'fs.suid_dumpable' ) . value == 2
336
+ end
337
+
328
338
describe kernel_parameter ( 'kernel.core_pattern' ) do
329
339
its ( :value ) { should match %r{^/.*} }
330
340
end
You can’t perform that action at this time.
0 commit comments