PT-1999-1569 · Tin · Tin

Published

1999-11-17

·

Updated

2016-10-18

·

CVE-1999-1092

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions tin version 1.40
Description The issue allows local users to read passwords from the .inputhistory file due to insecure permissions of the .tin directory created by the software.
Recommendations For tin version 1.40, consider changing the permissions of the .tin directory to secure it and prevent unauthorized access to the .inputhistory file. As a temporary workaround, restrict access to the .inputhistory file until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1092

Affected Products

Tin