znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
{ "urgency": "not yet assigned" }