A vulnerability has been identified in Debian, which could be exploited by attackers to bypass security restrictions. This issue is caused by an input validation error in the dpkg-source component of dpkg when extracting the content of a Debian source package, which could be exploited by attackers to manipulate files outside of the destination directory by tricking a user into extracting a malicious archive.
Debian GNU/Linux lenny - Upgrade to dpkg version 1.14.29
Debian GNU/Linux sid - A fix will be available soon
Debian GNU/Linux squeeze - A fix will be available soon