Ulf Härnhammar from the Debian Security Audit Project discovered a format string vulnerability in weex, a non-interactive FTP client for updating web pages, that could be exploited to execute arbitrary code on the clients machine.
For the old stable distribution (woody) this problem has been fixed in version 2.6.1-4woody2.
For the stable distribution (sarge) this problem has been fixed in version 2.6.1-6sarge1.
For the unstable distribution (sid) this problem has been fixed in version 2.6.1-6sarge1.
We recommend that you upgrade your weex package.
MD5 checksums of the listed files are available in the original advisory.