This issue is fixed since Version 2.03 from 4th of July 2007. See http://novemberborn.net/sifr/2.0.3 for the blog entry about this security fix.