logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15888
http://www.securityfocus.com/bid/10162
http://www.mandriva.com/security/advisories?name=MDKSA-2004:155