Ulf Härnhammar from the Debian Security Audit Project discovered a vulnerability in lbreakout2, a game, where proper bounds checking was not performed on environment variables. This bug could be exploited by a local attacker to gain the privileges of group "games".
For the current stable distribution (woody) this problem has been fixed in version 2.2.2-1woody1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you update your lbreakout2 package.
MD5 checksums of the listed files are available in the original advisory.