GNOME Bugzilla – Bug 593190
creates log files in shared directory with fixed name (/tmp/dogtail)
Last modified: 2009-10-20 16:29:19 UTC
Dogtail saves the log files in /tmp/dogtail instead of the current directory. Not only will this break if multiple users on the same host (e.g. a shared development server / build host) try to use it, but it also presents an opportunity for a symlink attack. This has been reported to Debian by someone else in 2008 (see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=485752 ), including a patch.
Thanks for your report. For some reason my mail server just delivered the notification for this bug today. For a long time, dogtail has made /tmp/dogtail/ and its subdirectories 0777 by default.