.xsession-errors file in user's home is open with root permissions without checking for symlinks.
vulners.com/securityvulns/securityvulns:doc:5020