Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.Referenceshttp://www.securityfocus.com/bid/64656http://marc.info/?l=oss-security&m=138900586911271&w=2http://www.ubuntu.com/usn/USN-2084-1http://secunia.com/advisories/56579http://www.debian.org/security/2014/dsa-2836http://secunia.com/advisories/56192https://exchange.xforce.ibmcloud.com/vulnerabilities/90107http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=02c6850d973e3e1246fde72edab27f03d63acc52