The old advisory said:
Zenith Parse found a security problem in groff (the GNU version of troff). The pic command was vulnerable to a printf format attack which made it possible to circumvent the `-S' option and execute arbitrary code.
MD5 checksums of the listed files are available in the original advisory.