The telnet daemon contained in the netkit-telnet-ssl_0.16.3-1 package in the 'stable' (potato) distribution of Debian GNU/Linux is vulnerable to an exploitable overflow in its output handling.
The Horde team released version 2.2.6 of IMP (a web based IMAP mailprogram) which fixes three security problems. Their release announcementdescribes them as follows: