So when '<' or '>' are found in the input we "pay for 1 and get 3 for free", this allows us overwrite bits of EBP and indirectly control EIP (assuming its been compiled with gcc < 3.0).
Workaround:
Upgrade to version 2.24
Disclosure Timeline:
09/08/2003: Vendor notified by e-mail
09/12/2003: Vendor replies with working fix
10/27/2003: Public release