mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.
http://www.securityfocus.com/templates/archive.pike?list=1&msg=15769.990928%40tomcat.ru
http://www.securityfocus.com/bid/681
http://www.novell.com/linux/security/advisories/suse_security_announce_22.html