Gentoo Linux Security Advisory GLSA 200809-13 - R is vulnerable to symlink attacks due to an insecure usage of temporary files. Dmitry E. Oboukhov reported that the javareconf script uses temporary files in an insecure manner. Versions less than 2.7.1 are affected.
7a6492d9f03e324b6a848b1b3fe59e88048ee6ac6f8f6d962b263f5af9b5b70f
Mandriva Linux Security Advisory - A symlink vulnerability was found in the javareconf script in R that allows local users to overwrite arbitrary files. The updated packages have been patched to prevent this issue.
b99d99c5158b1d3ecb006714bbc150f0f8ab552425f2bd64778e1edb59aea90e