Mandriva Security Advisory – Gnucash versions 2.0.4 and earlier allow local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54616/MDKSA-2007-046.txt
Source: https://packetstormsecurity.com/files/54616/Mandriva-Linux-Security-Advisory-2007.046.html

