It was discovered that xfce-terminal, a terminal emulator for the xfce
environment, did not correctly escape arguments passed to the processes
spawned by Open Link
. This allowed malicious links to execute arbitrary
commands upon the local system.
For the stable distribution (etch), this problem has been fixed in version 0.2.5.6rc1-2etch1.
For the unstable distribution (sid), this problem has been fixed in version 0.2.6-3.
We recommend that you upgrade your xfce4-terminal package.
MD5 checksums of the listed files are available in the original advisory.