latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libkpathsea-dev", "binary_version": "2013.20130729.30972-2build3" }, { "binary_name": "libkpathsea6", "binary_version": "2013.20130729.30972-2build3" }, { "binary_name": "libptexenc-dev", "binary_version": "2013.20130729.30972-2build3" }, { "binary_name": "libptexenc1", "binary_version": "2013.20130729.30972-2build3" }, { "binary_name": "texlive-binaries", "binary_version": "2013.20130729.30972-2build3" } ] }