The version of the ncurses display library shipped with Debian GNU/Linux
2.2 is vulnerable to several buffer overflows in the parsing of terminfo
database files. This problem was discovered by Jouko Pynnönen
<jouko@solutions.fi>. The problems are only exploitable in the
presence of setuid binaries linked to ncurses which use these particular
functions, including xmcd versions before 2.5pl1-7.1.
This problem is fixed in ncurses 5.0-6.0potato1 for Debian GNU/Linux 2.2,
and in ncurses 5.0-8 for Debian Unstable.