For the record, this issue is being tracked as CVE-2015-6908. http://www.openwall.com/lists/oss-security/2015/09/11/5