scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
https://exchange.xforce.ibmcloud.com/vulnerabilities/78977
http://www.ubuntu.com/usn/USN-1593-1
http://www.securityfocus.com/bid/55564
http://www.debian.org/security/2012/dsa-2549