Package: tnftp Severity: grave Tags: security Please see http://www.openwall.com/lists/oss-security/2014/10/28/4 No CVE ID has been assigned yet. This doesn't warrant a DSA, but you could fix it up in a point release. Cheers, Moritz