The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A554
http://www.securityfocus.com/bid/7107
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.redhat.com/support/errata/RHSA-2003-096.html
http://www.redhat.com/support/errata/RHSA-2003-095.html
http://www.novell.com/linux/security/advisories/2003_016_samba.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:032
http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml
http://www.debian.org/security/2003/dsa-262
http://secunia.com/advisories/8303
http://secunia.com/advisories/8299