Not sure how many people this effects, but I noticed the following:
catalog/includes/classes/sessions.php: $url = parse_url($GLOBALS['HTTP_REFERER']);
in the patched version. AFAIK, this needs to be changed to $_SERVER['HTTP_REFERER']. ALso exists in
catalog/admin/includes/classes/sessions.php: $url = parse_url($GLOBALS['HTTP_REFERER']);
Also the line right below in both of those files, dealing with SERVER_NAME...