Peter Samuelson, upstream maintainer of bmv, a PostScript viewer for SVGAlib, discovered that temporary files are created in an insecure fashion. A malicious local user could cause arbitrary files to be overwritten by a symlink attack.
For the stable distribution (woody) this problem has been fixed in version 1.2-14.2.
For the unstable distribution (sid) this problem has been fixed in version 1.2-17.
We recommend that you upgrade your bmv packages.
MD5 checksums of the listed files are available in the original advisory.