Stack-based buffer overflow in tmsnc allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an MSN packet with a UBX command containing a large UBX payload length field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/43297
http://www.securityfocus.com/bid/29850
http://security.gentoo.org/glsa/glsa-200903-26.xml