Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0414
http://www.redhat.com/support/errata/RHSA-2001-025.html
http://archives.neohapsis.com/archives/bugtraq/2001-03/0078.html