Debian Security Advisory DSA 1393-1 (xfce4-terminal)

Summary
The remote host is missing an update to xfce4-terminal announced via advisory DSA 1393-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201393-1
Insight
It was discovered that xfce-terminal, a terminal emulater for the xfce environment, did not correctly escape arguments passed to the processes spawned by Open Link. This allowed malicious links to execute arbitary commands upon the local system. For the stable distribution (etch), this problem has been fixed in version 0.2.5.6rc1-2etch1. For the unstable distribution (sid), this problem has been fixed in version 0.2.6-3. We recommend that you upgrade your xfce4-terminal package.