Busybox embeds mini-lzo library implementation which suffers
from CVE-2014-4607 -- integer overflow with memory corruption
potential and a risk of (remote) code execution, see
http://www.openwall.com/lists/oss-security/2014/06/26/20 for

This flaw has been fixed in busybox upstream in commit


 busybox (1:1.22.0-10) unstable; urgency=high
   * lzop-add-overflow-check-CVE-2014-4607.patch (Closes: #768945)
   * add Built-Using control field for -static, deriving it from
     regular build (this will be glibc) (Closes: #768926)
   * install only arch/indep deb as requested by binary-arch or binary-indep
     target.  This fixes a long-standing lintian error, when package build
     alway produces busybox-syslogd package which is arch:all and should not
     be built on a buildd.
