CVE-2009-3994 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3994): Stack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c in DevIL 1.7.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted DICOM file.
Patch in $URL.
That's not the version in portage.
Description, versioning and product link fitted, but now further research showed that the tree is similar, but il_dicom.c is missing. I'm not sure why yet.
Our current version in the tree is not affected, only 1.7.8 is. Games, please remember to update to an unaffected version when bumping.