From gnupg-announce:
Tavis Ormandy of the Gentoo security team identified a severe and
exploitable bug in the processing of encrypted packets in GnuPG.
You can see the whole message here:
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000491.html
The Win32 build can be found here:
ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.6.exe