CVE-2014-5260: XML-Dt Project XML-Dt

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.

Affected products

  • XML-Dt Project XML-Dt: up to and including 0.63; version 0.60 only; version 0.61 only; version 0.62 only

Published 2014-08-16. Last modified 2026-06-17.