The remote Debian host is missing a security-related update.
Danny Grander discovered a directory traversal flaw in plexus-archiver, an Archiver plugin for the Plexus compiler system, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted Zip archive.
Upgrade the plexus-archiver packages. For the oldstable distribution (jessie), this problem has been fixed in version 1.2-1+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 2.2-1+deb9u1.