Secunia Research has discovered a security issue in Bournal, which can be exploited by malicious, local users to perform certain actions with escalated privileges. The script uses temporary files in an insecure manner, which can be exploited to e.g. overwrite arbitrary files via symlink attacks when running the update check via the "--hack_the_gibson" parameter. Version 1.4 is affected.
a3704c22bb29dbe74497c72e16245dccd303f51f27b7e0ceadaa0047b32b368b