diff --git a/chapter06/bzip2.xml b/chapter06/bzip2.xml
index 6b401650f..bf13936c0 100644
--- a/chapter06/bzip2.xml
+++ b/chapter06/bzip2.xml
@@ -36,8 +36,10 @@ GCC, Glibc, and Make
patch -Np1 -i ../&bzip2-docs-patch;
-Bzgrep fails to sufficiently sanitise filenames passed
-to it. Apply the following to address this:
+Bzgrep does not escape '|' and '&' in filenames passed
+to it. This allows arbitrary commands to be executed with the privileges of the
+user running bzgrep. Apply the following to address this:
+
patch -Np1 -i ../&bzip2-bzgrep-patch;