The cupsomatic driver in foomatic has an issue where if a properly named file is handed to lpr for printing, it can cause arbitrary command execution. I'll attach the patch when it becomes available. This issue should also affect FC1.
Candidate packages built (FEDORA-2004-302, FEDORA-2004-303). Awaiting release date for push.
Removing embargo
FC4 includes the fixes.