K 10 svn:author V 4 stas K 8 svn:date V 27 2009-09-14T20:06:29.000000Z K 7 svn:log V 448 - Fix formatting. - Add link to the debian security advisory. - Fix the description to be the actual citation from the official sources instead of some wild interpretation. We do not know for sure if remote code execution is possible at all and from looking to the source code it seems unlikely as the buffer undeflown is allocated on the heap. Moreover, it is not clear if this is exploitable in the default install. Discussed with: az END