The script uses e.g. the insecure "-K" command line parameter to pass the key to the ccrypt utilities, which can be exploited to obtain the key from the list of running processes.
Note: This may not affect recent Linux versions, but is confirmed for FreeBSD 8.0. Other systems may also be affected.