A new Debian Linux update has been published: ELA-237-1 batik security update
A batik security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where the Apache Batik library can be made to perform arbitrary GET requests via xlink:href attributes on SVG files.Read more @ Linux Compatible