cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.Referenceshttp://www.securityfocus.com/bid/32741http://lists.debian.org/debian-devel/2008/08/msg00347.htmlhttp://secunia.com/advisories/33113http://uvw.ru/report.sid.txt