This problem has been fixed by the maintainer in version 2.1-13 of xvt for Debian unstable and 2.1-13.0potato.1 for the stable Debian GNU/Linux 2.2.
We recommend that you upgrade your xvt package immediately.
MD5 checksums of the listed files are available in the original advisory.