SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
https://www.exploit-db.com/exploits/40230/
http://www.securityfocus.com/bid/92406
http://www.securityfocus.com/archive/1/539180/100/0/threaded