See http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=600129 (not a buffer overflow, but a different type of bug)