hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugindebugoptim_results.txt temporary file.
{ "urgency": "low" }