znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
http://www.turbolinux.com/security/TLSA-2003-38.txt
http://www.securityfocus.com/bid/7872
http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:068