CVE-1999-1091
Executive Summary
The CVE-1999-1091 vulnerability in the UNIX news readers tin and rtin allows a local attacker to exploit insecure permissions on /tmp/.tin_log by creating a symlink to a writable file. Following the symlink lets the attacker modify file permissions, potentially enabling privilege escalation or unauthorized data tampering. The flaw is not currently listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 5.0 (MEDIUM) - Published: 2002-01-15T05:00:00.000 - Last Modified: 2026-09-25T20:10:00.123
Original Description: UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.
"We are the leaves of one branch, the drops of one sea, the flowers of one garden."
— Jean Lacordaire