The tmpwatch utility is used in Red Hat Linux to remove temporary files. This utility has an option to call the fuser program, which verifies if a file is currently opened by a process. The fuser program is invoked within tmpwatch by calling the system() library subroutine. Insecure handling of the arguments to this subroutine could potentially allow an attacker to execute arbitrary commands.
3a65b520b3913eeaf250c2b7af29ca697b1fcffe8b6368c569d85201f43b3ff9