SECURITY UPDATE: heap-based buffer overflows in Heimdal ARC4 and DES3
debian/patches/CVE-2022-3437.patch: add extra NULL pointer and buffer
boundaries checks, fix undefined behaviour and input data length
calculations, remove accidentally duplicated code in arcfour.c