Ubuntu Security Notice 847-2 - USN-847-1 fixed vulnerabilities in devscripts. This update provides the corresponding updates for Ubuntu 6.06 LTS. Raphael Geissert discovered that uscan, a part of devscripts, did not properly sanitize its input when processing pathnames. If uscan processed a crafted filename for a file on a remote server, an attacker could execute arbitrary code with the privileges of the user invoking the program.
a0c0a418e5ffcdc58b1be1ff537ea8f50f3ede9d95754dd6f137056600238dad