Yes, this indicates a buffer overflow, which is a security issue. This is something that you should report upstream. That said, the pkgsrc package is an older version, and version 2.23-08 (released in 2013!) says in the release notes that it fixes a buffer overflow.