This was the security issue reported at OSVDB for ANTLR versions lower than 4.1 http://osvdb.org/show/osvdb/95378