Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
{ "urgency": "not yet assigned" }