CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A80
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2770
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A175
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0207-199
http://www.securityfocus.com/bid/5083
http://www.iss.net/security_center/static/9527.php
http://marc.info/?l=bugtraq&m=102635906423617&w=2
http://archives.neohapsis.com/archives/aix/2002-q3/0002.html