CVE-2014-5260
16.08.2014, 04:39
The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.
| Vendor | Product | Version |
|---|---|---|
| xml-dt_project | xml-dt | 𝑥 ≤ 0.63 |
| xml-dt_project | xml-dt | 0.60 |
| xml-dt_project | xml-dt | 0.61 |
| xml-dt_project | xml-dt | 0.62 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References