Mailing the story:
Debian alert: New crawl packages fix potential local games exploit
"Steve Kemp from the GNU/Linux audit project discovered a problem in
crawl, another console based dungeon exploration game, in the vein of
nethack and rogue. The program uses several environment variables as
inputs but doesn't apply a size check before copying one of them into
a fixed size buffer."