Debian Security Advisory 1328-1 – Steve Kemp from the Debian Security Audit project discovered that unicon-imc2, a Chinese input method library, makes unsafe use of an environmental variable, which may be exploited to execute arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57386/dsa-1328-1.txt
Source: https://packetstormsecurity.com/files/57386/Debian-Linux-Security-Advisory-1328-1.html

