The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18646
http://www.securityfocus.com/bid/12078