Phil Shafer <phil@juniper.net> pointed buffer overrun case and fix it. Please add following patch.
State Changed From-To: open->closed Committed, thanks!