Any user who can submit a job can cause a buffer overflow in the condor_schedd. condor_qedit 1.0 X 1, for instance, sets attribute X to 1 on job 1.0. The attribute name X is used to lookup configuration information, which employs a static 1024 byte buffer. Making the attribute name large enough can overflow that buffer. The condor_schedd is a root run service.
Lifting embargo: http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000
condor-7.0.5-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Red Hat Enterprise MRG for RHEL-4: http://rhn.redhat.com/errata/RHSA-2008-0924.html Red Hat Enterprise MRG for RHEL-5: http://rhn.redhat.com/errata/RHSA-2008-0911.html Fedora: https://admin.fedoraproject.org/updates/F9/FEDORA-2008-8733