Debian Security Advisory 1654-1 – It was discovered that libxml2, the GNOME XML library, didn’t correctly handle long entity names. This could allow the execution of arbitrary code via a malicious XML file.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/70915/dsa-1654-1.txt
Source: https://packetstormsecurity.com/files/70915/Debian-Linux-Security-Advisory-1654-1.html