October 4, 2009, 5:00 pm
Jakub Wilk discovered an off-by-one buffer overflow in the charset handling of elinks, a feature-rich text-mode WWW browser, which might lead to the execution of arbitrary code if the user is tricked into opening a malformed HTML page.
For the old stable distribution (etch), this problem has been fixed in version 0.11.1-1.2etch2.
The stable distribution (lenny) and the unstable distribution (sid) already contain a patch for this problem.
We recommend that you upgrade your elinks package...