TUCoPS :: Unix :: General :: ciaca13.txt

Vulnerability in DECODE alias




                        INFORMATION BULLETIN


                Vulnerability in DECODE alias

January 19, 1990, 1600 PST                                      Number A-13

CIAC has learned of a UNIX vulnerability in the DECODE alias.  There

is a strong possibility that this vulnerability is currently being

exploited.  One workaround is to disable the DECODE alias by

commenting out the line beginning with DECODE in either /etc/aliases

or /usr/lib/aliases.  If you do not wish to disable the DECODE alias,

you can redirect DECODE to postmaster.

If you have questions, please contact CIAC.


        Tom Longstaff

        (415) 423-4416 or (FTS) 543-4416

        FAX: (FTS) 543-0913 or (415) 294-5054  

CIAC's business hours phone number is (415) 422-8193 or (FTS) 532-8193.  

CIAC's 24-hour emergency hot-line number is (415) 971-9384

or send e-mail to:


Neither the United States Government nor the University of California

nor any of their employees, makes any warranty, express or implied, or

assumes any legal liability or responsibility for the accuracy,

completeness, or usefulness of any information, product, or process

disclosed, or represents that its use would not infringe privately

owned rights.  Reference herein to any specific commercial products,

process, or service by trade name, trademark manufacturer, or

otherwise, does not necessarily constitute or imply its endorsement,

recommendation, or favoring by the United States Government or the

University of California.  The views and opinions of authors expressed

herein do not necessarily state or reflect those of the United States

Government nor the University of California, and shall not be used for

advertising or product endorsement purposes.

