Debian Security Advisory 1465-2 – Felipe Sateler discovered that apt-listchanges, a package change history notification tool, used unsafe paths when importing its python libraries. This could allow the execution of arbitrary shell commands if the root user executed the command in a directory which other local users may write to. This security update fixes a regression in the previous one, which caused the package to fail to work.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/62749/dsa-1465-2.txt
Source: https://packetstormsecurity.com/files/62749/Debian-Linux-Security-Advisory-1465-2.html

