A buffer overflow has been discovered in the Xpm library which is used in XFree86. A remote attacker could provide a specially crafted XPM image that could lead to the execution of arbitrary code.
For the stable distribution (woody) this problem has been fixed in version 4.1.0-16woody6.
For the unstable distribution (sid) this problem will be fixed in version 4.3.0.dfsg.1-13, which is currently in preparation.
We recommend that you upgrade your xfree86 and associated packages.
MD5 checksums of the listed files are available in the original advisory.