Nikolaus Schulz discovered that a programming error in id3lib, an ID3 Tag Library, may lead to denial of service through symlink attacks.
For the oldstable distribution (sarge) this problem has been fixed in version 3.8.3-4.1sarge1.
Due to a technical limitation in the archive management scripts the fix for the stable distribution (etch) can only be released in a few days.
For the unstable distribution (sid) this problem has been fixed in version 3.8.3-7.
We recommend that you upgrade your id3lib3.8.3 packages.
MD5 checksums of the listed files are available in the original advisory.