ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
https://github.com/advisories/GHSA-5pjj-7m4p-wfh2
https://exchange.xforce.ibmcloud.com/vulnerabilities/64892