sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVSS Metrics