Updated xdg-utils package fixes security vulnerability:
John Houwer discovered a way to cause xdg-open, a tool that automatically opens URLs in a user's preferred application, to execute arbitrary commands remotely (CVE-2014-9622).
The xdg-utils has been updated to a much more recent snapshot, and has been patched to fix this issue.