The version of splitvt distributed in Debian GNU/Linux 2.1
(a.k.a. slink), as well as in the frozen (potato) and unstable (woody)
distributions, is vulnerable to a local buffer overflow. This could be
exploited to give a shell running as root. This has been fixed in versions
1.6.3-7.0slink1 (for slink) and 1.6.3-7.1 (for potato), and we recommend that
you update your splitvt package immediately.