Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
https://exchange.xforce.ibmcloud.com/vulnerabilities/90107
http://www.ubuntu.com/usn/USN-2084-1
http://www.securityfocus.com/bid/64656
http://www.debian.org/security/2014/dsa-2836
http://secunia.com/advisories/56579
http://secunia.com/advisories/56192