The remote Debian host is missing a security-related update.
Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to overwrite any file writable by the user running ant.
Upgrade the ant packages. For the stable distribution (stretch), this problem has been fixed in version 1.9.9-1+deb9u1.