security release, fixing issue with as-yet-unassigned CVE. debian are using DSA-4473-1/DLA-1837-1. switching to github source because they don't seem to be keeping their sourceforge tarballs up to date