Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
https://lists.gnu.org/archive/html/lout-users/2019-12/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00069.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00068.html