Tim Waugh found several insecure uses of temporary files in the xsane program, which is used for scanning. This was fixed for Debian/stable by moving those files into a securely created directory within the /tmp directory.
This problem has been fixed in version 0.50-5.1 for the stable Debian distribution and in version 0.84-0.1 for the testing and unstable distribution of Debian.
We recommend that you upgrade your xsane package.
MD5 checksums of the listed files are available in the original advisory.