CVE-2014-5260
The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 11.8%
EPSS: 2026-05-06
Affects
xml-dt_project:xml-dtTechnical description
The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.
Published: 8/16/2014, 4:39:55 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://openwall.com/lists/oss-security/2014/08/15/8
- https://bugs.debian.org/756566
- https://metacpan.org/diff/file?target=AMBS/XML-DT-0.64/&source=AMBS/XML-DT-0.63/
- https://metacpan.org/source/AMBS/XML-DT-0.66/Changes
- http://openwall.com/lists/oss-security/2014/08/15/8
- https://bugs.debian.org/756566
- https://metacpan.org/diff/file?target=AMBS/XML-DT-0.64/&source=AMBS/XML-DT-0.63/
- https://metacpan.org/source/AMBS/XML-DT-0.66/Changes