﻿id	summary	reporter	owner	description	type	status	component	version	resolution	keywords	cc	guest	host
15069	Minor issue with file permissions - fail SCAP security validation -> fixed in releases higher than 5.0.14	VirtualBarista		"OpenSCAP (SCAP) security validation (CCE-26966-2, reference AC-6) requires that the following directories:

/lib
/lib64
/usr/lib
/usr/lib64

do not contain any group (or world) writable files.

unfortunately, when guest additions are installed in a CentOS 7 guest server, there are two files that fail this validation (they are group writable):

/lib/modules/*/misc/vboxguest.ko
/lib/modules/*/misc/vboxsf.ko

(also linked via /usr/lib)

While this is a minor issue (guest writable by root only), it does make the entire security validation fail.

Thank you!

"	defect	closed	guest additions	VirtualBox 5.0.14	fixed			Linux	Linux
