This problem has been fixed in version 3.20 by the upstream maintainer, included in Debian unstable, and was ported back to version 3.15.2 which is available for the stable Debian GNU/Linux 2.2.
We recommend that you upgrade your procmail package immediately.
MD5 checksums of the listed files are available in the original advisory.