lib/Locale/Po4a/Po
lib/Locale/Po4a/Po.pm in po4a before 0.32 allows local users to overwrite arbitrary files via a symlink attack on the gettextization.failed.po temporary file.
Exploitability
AV:L
AC:M
Au:N
Impact
C:N
I:P
A:P
3.3/AV:L/AC:M/Au:N/C:N/I:P/A:P