tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
{ "binaries": [ { "binary_name": "pktstat", "binary_version": "1.8.5-3" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }