add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file.Referenceshttp://lists.debian.org/debian-devel/2008/08/msg00347.htmlhttp://uvw.ru/report.sid.txt