Launchpad.net

CVE 2014-3986

include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.

See the CVE page on Mitre.org for more details.