wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00841.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00825.html
https://bugzilla.redhat.com/show_bug.cgi?id=433719
http://www.securityfocus.com/bid/27848