Debian Security Advisory 1393-1 – It was discovered that xfce-terminal, a terminal emulator for the xfce environment, did not correctly escape arguments passed to the processes spawned by “Open Link”. This allowed malicious links to execute arbitrary commands upon the local system.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60355/dsa-1393-1.txt
Source: https://packetstormsecurity.com/files/60355/Debian-Linux-Security-Advisory-1393-1.html

