tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/23858
http://www.securityfocus.com/bid/16064
http://www.mandriva.com/security/advisories?name=MDKSA-2006:001
http://www.debian.org/security/2005/dsa-927
http://sourceforge.net/project/shownotes.php?release_id=380030&group_id=64960
http://securitytracker.com/id?1015421