Tavis Ormandy from the Google Security Team discovered a missing boundary check in ncompress, the original Lempel-Ziv compress and uncompress programs, which allows a specially crafted datastream to underflow a buffer with attacker controlled data.
For the stable distribution (sarge) this problem has been fixed in version 4.2.4-15sarge2.
For the unstable distribution (sid) this problem has been fixed in version 4.2.4-15sarge2.
We recommend that you upgrade your ncompress package.
MD5 checksums of the listed files are available in the original advisory.