Debian Security Advisory 1554-1 – Roundup, an issue tracking system, fails to properly escape HTML input, allowing an attacker to inject client-side code (typically JavaScript) into a document that may be viewed in the victim’s browser.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65713/dsa-1554-1.txt
Source: https://packetstormsecurity.com/files/65713/Debian-Linux-Security-Advisory-1554-1.html