Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=02c6850d973e3e1246fde72edab27f03d63acc52
marc.info/?l=oss-security&m=138900586911271&w=2
secunia.com/advisories/56192
secunia.com/advisories/56579
www.debian.org/security/2014/dsa-2836
www.securityfocus.com/bid/64656
www.ubuntu.com/usn/USN-2084-1
exchange.xforce.ibmcloud.com/vulnerabilities/90107