LCDproc v0.4.5, a new stable version, has been released. This release fixes two buffer overflow/format string vulnerabilities. It is recommended that all users upgrade to this release immediately as an exploit has been posted to bugtraq.
LCDproc controls various LCD and VFD devices in a standardized way, and ships with a client to display various system statistics. Supports multiple platforms (Linux, *BSD, Solaris). Client/server model allows multiple systems/clients to use one display.
Please note that the LCDproc developers have not been notified of the bugtraq posting before or after it was published and have not had the chance to react to it any earlier.
More information is available at http://lcdproc.org/ or in the advisory at http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html