Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.
http://www.securityfocus.com/bid/38353
http://www.securityfocus.com/archive/1/509685/100/0/threaded
http://secunia.com/secunia_research/2010-6/
http://secunia.com/advisories/38814
http://secunia.com/advisories/38554
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html