Tiger Security Tool Temporary Files Race Condition and Symlink
Local Access Required
Tiger Security Scanner contains a flaw that allows local attackers to overwrite arbitrary files or possibly gain root priveleges. The flaw is due to a lack of sanity checking on calls to temporary files created in /tmp that do not check for existing files with the same name. Such flaws can be taken advantage of with symlinks and arbitrary files can be overwritten or appended to.
Upgrade to version 3.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.