ELBA-2022-10103

ELBA-2022-10103 - scap-security-guide bug fix update

Type:BUG
Impact:NA
Release Date:2022-12-22

Description


[0.1.63-4.0.2]
- Update rules that modify pwquality.conf to delete confs in pwquality.conf.d
so it ensures no wrong confs exist [Orabug: 34893225]
- Allow several non-conflicting entries of the timestamp_timeout config entry
in sudoers files [Orabug: 34893225]
- Update fapolicy_default_deny to look into compiled.rules [Orabug: 34893225]
- Align OL08-00-020352 better by ignoring .bash_history file, and OL08-00-010120
by better detect locked passwords [Orabug: 34893225]
- Update rules dealing with sshd_config to look into files added to the include
keyword [Orabug: 34893225]
- Update remediations in two rules which wasn't letting the system boot when
running anssi-high profile [Orabug: 34893225]
- Update STIG version to V1R4 [Orabug: 34893225]
- Update rules accounts_password_set_min_life_existing and
accounts_password_set_max_life_existing to ignore non-interactive users
[Orabug: 34905591]




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) scap-security-guide-0.1.63-4.0.2.el8.src.rpm3ef5390904e2fc39fd28017458b122e7c4614177cf0428cfe08c233c970643b3-ol8_aarch64_appstream
scap-security-guide-0.1.63-4.0.2.el8.noarch.rpma790b16679c58062e8df85d7a15adb74b73f63f33a499ce7c41a44c3c57ece06-ol8_aarch64_appstream
scap-security-guide-doc-0.1.63-4.0.2.el8.noarch.rpmd308bf21e6b38058feee69360bfd5a9e15d9f3e3bd7b2f6cfaafa998ea1fbe82-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) scap-security-guide-0.1.63-4.0.2.el8.src.rpm3ef5390904e2fc39fd28017458b122e7c4614177cf0428cfe08c233c970643b3-ol8_x86_64_appstream
scap-security-guide-0.1.63-4.0.2.el8.noarch.rpma790b16679c58062e8df85d7a15adb74b73f63f33a499ce7c41a44c3c57ece06-ol8_x86_64_appstream
scap-security-guide-doc-0.1.63-4.0.2.el8.noarch.rpmd308bf21e6b38058feee69360bfd5a9e15d9f3e3bd7b2f6cfaafa998ea1fbe82-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete