Debian Security Advisory DSA 1704-2 – The update in DSA 1704-1 was incomplete as it missed to escape a few important characters which enabled an attacker to overwrite arbitrary files.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74487/dsa-1704-2.txt
Source: https://packetstormsecurity.com/files/74487/Debian-Linux-Security-Advisory-1704-2.html