 






          DIGITAL

          CUSTOMER LETTER OF NOTIFICATION

          AV-PG5CA-TE

          January 11, 1991

          Dear VMS/ULTRIX Connection Customer,

          Digital Engineering has recently discovered a problem
          in Version 1.3A of the VMS/ULTRIX Connection that
          relates to file access control.

          To improve your system's security, we strongly recom-
          mend that you perform the following steps immediately.
          Please follow these instructions carefully in order to
          properly implement the recommended correction.

          1. Modify UCX$FTPD_STARTUP.COM so that UCX$FTPC.EXE
             installs with OPER privilege instead of SYSPRV.

             Do this by changing the following DCL program state-
             ment in UCX$FTPD_STARTUP.COM:

                  $ IF .NOT. F$FILE("''LIBRARY'","KNOWN") -
                     THEN INSTALL CREATE 'LIBRARY'/HEADER/SHARED-
                     /PRIVILEGED=(SYSPRV,NETMBX)

             Change the third line so that the /PRIVILEGED quali-
             fier is set to OPER, as follows:

                  $ IF .NOT. F$FILE("''LIBRARY'","KNOWN") -
                     THEN INSTALL CREATE 'LIBRARY'/HEADER/SHARED-
                     /PRIVILEGED=(OPER,NETMBX)

          2. Shut down FTP with the following command:

                  $ @SYS$MANAGER:UCX$FTPD_SHUTDOWN

 


                                                           Page 2



          3. Start up FTP with the following command:

                  $ @SYS$MANAGER:UCX$FTPD_STARTUP

          We apologize for any inconvenience these extra steps
          will cause you. If you have any further questions
          regarding this letter, please contact your Customer
          Support Center.








          The following are trademarks of Digital Equipment
          Corporation: VMS, ULTRIX, VMS/ULTRIX Connection.

          Digital Equipment Corporation. 1991. All rights re-
          served.
