syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
http://www.vupen.com/english/advisories/2005/2308
http://www.securityfocus.com/bid/15320
http://www.debian.org/security/2005/dsa-883