latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
{ "binaries": [ { "binary_version": "2013.20130729.30972-2build3", "binary_name": "libkpathsea-dev" }, { "binary_version": "2013.20130729.30972-2build3", "binary_name": "libkpathsea6" }, { "binary_version": "2013.20130729.30972-2build3", "binary_name": "libptexenc-dev" }, { "binary_version": "2013.20130729.30972-2build3", "binary_name": "libptexenc1" }, { "binary_version": "2013.20130729.30972-2build3", "binary_name": "texlive-binaries" } ], "availability": "No subscription required" }