There are two potential issues with the malleability. One is the MtGox problem where you might not realize a transaction was successful and you are duped into sending the money twice.
The second issue is a bug that was discovered in the reference client where if you try to spend coins you sent to yourself before they are confirmed a bug in the wallet causes your balance to be off.
Neither problem inherently allows theft but if you aren't careful the first can open your to social engineering. The reason they are calling this a dos as far as I can tell is because they are preventing you from spending your money until the bug is fixed with the accounting in the reference wallet.
SR2 is probably full of crap but there is a small possibility that they some how automated re-sending of failed transactions w/o properly accounting for malleability in which case you might be able to steal a multiple of the actual amount of money in your account over a few days. The sheer size of this though would make me skeptical of that scenario.