flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/46717
http://www.securityfocus.com/bid/32386
http://www.debian.org/security/2008/dsa-1676
http://secunia.com/advisories/32961
http://secunia.com/advisories/32891