latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
{
"binaries": [
{
"binary_name": "libkpathsea-dev",
"binary_version": "2013.20130729.30972-2build3"
},
{
"binary_name": "libkpathsea6",
"binary_version": "2013.20130729.30972-2build3"
},
{
"binary_name": "libptexenc-dev",
"binary_version": "2013.20130729.30972-2build3"
},
{
"binary_name": "libptexenc1",
"binary_version": "2013.20130729.30972-2build3"
},
{
"binary_name": "texlive-binaries",
"binary_version": "2013.20130729.30972-2build3"
}
],
"availability": "No subscription required"
}