CVE-2014-5260
Published Aug 16, 2014
Last updated 10 years ago
Overview
- Description
- The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.
- Source
- security@debian.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.3
- Impact score
- 9.2
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:N/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-59
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:xml-dt_project:xml-dt:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "724D0ECB-58AC-40F7-AAD4-AD37C6CA098F", "versionEndIncluding": "0.63" }, { "criteria": "cpe:2.3:a:xml-dt_project:xml-dt:0.60:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5652C56-981C-45B1-AB98-9B58842B64D6" }, { "criteria": "cpe:2.3:a:xml-dt_project:xml-dt:0.61:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D14D9B0-1D69-4A0C-B3E7-2EDDA05397A8" }, { "criteria": "cpe:2.3:a:xml-dt_project:xml-dt:0.62:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1B58339-9878-4BE0-A7CC-E4C12C28421C" } ], "operator": "OR" } ] } ]