The issue is tracked by the security team as
<URL: >.

I guess the easiest fix is to upgrade the unstable version from upstream,
as the older versions of Debian are not affected and a quick search did not
point me to a patch.

Happy hacking
Petter Reinholdtsen

