From the Red Hat bugzilla:
The "distcheck" Makefile rule in coreutils 5.2.1 through to 8.1
did use unsafe (predictable) temporary directory location for
performing own tasks. This might allow local attacker to conduct
symlink attacks under certain circumstances.