Johnny Mast discovered a buffer overflow in libast, the library of assorted spiffy things, that can lead to the execution of arbitrary code. This library is used by eterm which is installed setgid uid which leads to a vulnerability to alter the utmp file.
For the old stable distribution (woody) this problem has been fixed in version 0.4-3woody2.
For the stable distribution (sarge) this problem has been fixed in version 0.6-0pre2003010606sarge1.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you upgrade your libast packages.
MD5 checksums of the listed files are available in the original advisory.