Stephen Gran and Mark Hymers discovered that some scripts run by GForge, a collaborative development tool, open files in write mode in a potentially insecure manner. This may be exploited to overwrite arbitary files on the local system.
For the stable distribution (etch), this problem has been fixed in version 4.5.14-22etch8.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your gforge package.
MD5 checksums of the listed files are available in the original advisory.