Gentoo Linux Security Advisory GLSA 200909-08 – An insecure temporary file usage has been reported in the C* music player, allowing for symlink attacks. Dmitry E. Oboukhov reported that cmus-status-display does not handle the /tmp/cmus-status temporary file securely. Versions less than 2.2.0-r1 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81090/glsa-200909-08.txt
Source: https://packetstormsecurity.com/files/81090/Gentoo-Linux-Security-Advisory-200909-8.html

