Debian Security Advisory DSA 2253-1 (fontforge)

Summary
The remote host is missing an update to fontforge announced via advisory DSA 2253-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202253-1
Insight
Ulrik Persson reported a stack-based buffer overflow flaw in FontForge, a font editor. When processed a crafted Bitmap Distribution Format (BDF) FontForge could crash or execute arbitrary code with the privileges of the user running FontForge. For the oldstable distribution (lenny), this problem has been fixed in version 0.0.20080429-1+lenny2. For the stable distribution (squeeze), testing distribution (wheezy), and unstable distribution (sid) are not affected by this problem. We recommend that you upgrade your fontforge packages.