tiff2pdf buffer overflow A buffer overflow flaw has been found in tiff2pdf. Thomas Biege told vendor-sec about this (it came from a colleague of his) The code in question is as such: char buffer[5]; ... sprintf(buffer, "\\%.3o", pdfstr[i]); pdfstr[i] is signed char, therefore would write \37777777741 This issue also affects FC4
Fixed in FC5 by libtiff-3.8.2-1.fc6.
(or better by its equvalent in FC5: libtiff-3.8.2-1.fc5)