latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.Referenceshttp://www.openwall.com/lists/oss-security/2012/04/19/12http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779http://www.openwall.com/lists/oss-security/2012/04/19/15