Steve Kemp and James Antill found several buffer overflows in the gtetrinet (a multiplayer tetris-like game) package as shipped in Debian GNU/Linux 3.0, which could be abused by a malicious server.
This has been fixed in upstream version 0.4.4 and release 0.4.1-9woody1.1 of the Debian package.
MD5 checksums of the listed files are available in the original advisory.