langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
http://www.securityfocus.com/bid/14561
http://www.mandriva.com/security/advisories?name=MDKSA-2005:159
http://www.kde.org/info/security/advisory-20050815-1.txt
http://www.debian.org/security/2005/dsa-818