Debian Security Advisory 1554-2 – Roundup, an issue tracking system, fails to properly escape HTML input, allowing an attacker to inject client-side code (typically JavaScript) into a document that may be viewed in the victim’s browser.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66034/dsa-1554-2.txt
Source: https://packetstormsecurity.com/files/66034/Debian-Linux-Security-Advisory-1554-2.html

