The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18922
http://www.securityfocus.com/bid/12277
http://www.debian.org/security/2005/dsa-647
http://secunia.com/advisories/13867
http://marc.info/?l=bugtraq&m=110608297217224&w=2
http://lists.mysql.com/internals/20600
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947