Mailing the story:
Debian alert: New radiusd-cistron packages fix buffer overflow
radiusd-cistron contains a bug allowing a buffer overflow when a long
NAS-Port attribute is received. This could allow a remote attacker to
execute arbitrary code on the with the privileges of the RADIUS daemon
(usually root).