XBoard contains a flaw which insecurely creates a file in /tmp with a predictable file name allowing a symlink attack. A malicious local user could use this flaw to create or overwrite files with the privileges/UID of another user.
Classification
Unknown or Incomplete
Solution
Upgrade to version 4.2.7 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by replacing the pxboard script with the one provided by vulnerability reporter.