emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/59045
http://www.vupen.com/english/advisories/2010/1423
http://www.securityfocus.com/bid/40455
http://secunia.com/advisories/40115
http://secunia.com/advisories/39945
http://marc.info/?l=oss-security&m=127514641525366&w=2
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042725.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042699.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042683.html