lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
https://exchange.xforce.ibmcloud.com/vulnerabilities/57457
https://bugs.launchpad.net/ubuntu/+bug/531569
http://www.vupen.com/english/advisories/2010/0952
http://www.vupen.com/english/advisories/2010/0734
http://www.ubuntu.com/usn/USN-919-1
http://www.mandriva.com/security/advisories?name=MDVSA-2010:083