xpdf as distributed in Debian GNU/Linux 2.2 suffered from two problems:
creation of temporary files was not done safely which made xpdf
vulnerable to a symlink attack.
when handling URLs in documents no checking was done for shell
metacharacters before starting the browser. This makes it possible
to construct a document which cause xpdf to run arbitrary commands
when the user views a URL.
Both problems have been fixed in version 0.90-7, and we recommend you
upgrade your xpdf package immediately.