* fixes a few security related issues and a good number of bugs from Brad
- also fix CFLAGS so it's not inserting -O2 unconditionally from brad