________________________________________________________________________ THE COMPUTER INCIDENT ADVISORY CAPABILITY CIAC INFORMATION BULLETIN ________________________________________________________________________ Vulnerability in DECODE alias January 19, 1990, 1600 PST Number A-13 CIAC has learned of a UNIX vulnerability in the DECODE alias. There is a strong possibility that this vulnerability is currently being exploited. One workaround is to disable the DECODE alias by commenting out the line beginning with DECODE in either /etc/aliases or /usr/aliases. If you do not wish to disable the DECODE alias, you can redirect DECODE to postmaster. If you have questions, please contact CIAC: Eugene Schultz (415) 422-8193 or (FTS) 532-8193 FAX: (415) 423-0913 or (FTS) 543-0913 CIAC's 24-hour emergency hot-line number is (415) 971-9384 or send e-mail to: ciac@tiger.llnl.gov Neither the United States Government nor the University of California nor any of their employees, makes any warranty, expressed or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed, or represents that its use would not infringe privately owned rights. Reference herein to any specific commercial products, process, or service by trade name, trademark manufacturer, or otherwise, does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government or the University of California. The views and opinions of authors expressed herein do not necessarily state or reflect those of the United States Government nor the University of California, and shall not be used for advertising or product endorsement purposes.