Hi, utu.

Debian is well aware:

https://security-tracker.debian.org/.../CVE-2014-9295

I am sure KK also knows and is just waiting for the Debian maintainer/packer to move.