Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.Referenceshttp://www.securityfocus.com/archive/1/509685/100/0/threadedhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.htmlhttp://secunia.com/advisories/38554http://secunia.com/secunia_research/2010-6/http://secunia.com/advisories/38814http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.htmlhttp://www.securityfocus.com/bid/38353