PT-1999-1569 · Tin · Tin
Published
1999-11-17
·
Updated
2016-10-18
·
CVE-1999-1092
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
tin version 1.40
Description
The issue allows local users to read passwords from the .inputhistory file due to insecure permissions of the .tin directory created by the software.
Recommendations
For tin version 1.40, consider changing the permissions of the .tin directory to secure it and prevent unauthorized access to the .inputhistory file. As a temporary workaround, restrict access to the .inputhistory file until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tin