CID 1201 - What is being checked?

Question asked by Scr1ptW1zard on Jun 8, 2012
Latest reply on Jun 12, 2012 by Jason Creech

I have the control (1201 - Status of the 'root user's $PATH variable' (if dot '.' exists) and current list of 'root-owned directories') included in my UNIX policy. This control is failing even when the actual $PATH variable does not contain a '.'. I checked the regular expression using the RegexTester ( and turns out that the regular expression is triggering on the string "::" (double colon) that is in the $PATH variable. My background is the Windows operating system, so my question is, what is the significance for checking for the double colon?