r22852: merge fixes for CVE-2007-2446 and CVE-2007-2447 to all branches