Jeroen van Wolffelaar <jeroen> discovered an insecure temporary file vulnerability in the mysqlhotcopy script when using the scp method. Sergei Golubchik <serg> has fixed this upstream with this patch: http://lists.mysql.com/internals/15185 This issue should also affect FC1.
Fixed in mysql-3.23.58-11 and later.
Thanks for the bug report. This particular bug was fixed and a update package was published for download. Please feel free to report any further bugs you find.