viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
rogers software source mgdiff patch viewer 1.0