The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/23863
https://bugzilla.mozilla.org/show_bug.cgi?id=305353
http://www.securityfocus.com/bid/16061
http://www.securityfocus.com/archive/1/420353/100/0/threaded
http://www.debian.org/security/2006/dsa-1208
http://securitytracker.com/id?1015411
http://securityreason.com/securityalert/302
http://secunia.com/advisories/22826