Orville Write, a replacement for the standard write(1) command, contains a number of buffer overflows. These could be exploited to gain either gid tty or root privileges, depending on the configuration selected when the package is installed.
For the stable distribution (woody) this problem has been fixed in version 2.53-4woody1.
The old stable distribution (potato) does not contain an orville-write package.
For the unstable distribution (sid) this problem will be fixed soon. See Debian bug report #170747.
We recommend that you update your orville-write package.
MD5 checksums of the listed files are available in the original advisory.