everybuddy 0.4.3 and previous versions allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
everybuddy everybuddy