Security Advisory
CVE-2005-4534
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.