cman has an insecure temp file vulnerability. From the Red Hat
bug report:
The fence_apc and fence_apc_snmp programs, as used in
fence 2.02.00-r1 and possibly cman, when running in verbose mode,
allows local users to append to arbitrary files via a symlink attack
on the apclog temporary file.