The send-pr.sh script creates temporary files in world-writeable
directories with predictable names. A local attacker could create symbolic
links in the temporary files directory, pointing to a valid file somewhere
on the filesystem. When send-pr.sh is called, this would result in the file
being overwritten with the rights of the user running the utility, which
could be the root user.