Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.Referenceshttp://www.securityfocus.com/bid/10060http://security.gentoo.org/glsa/glsa-200404-01.xmlhttp://secunia.com/advisories/11305https://exchange.xforce.ibmcloud.com/vulnerabilities/15754