The libtiff utility tiffdump contains an integer overflow which can be triggered when operating in a directory containing a large number of files. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2218
Statement: This flaw has already been fixed in Red Hat Enterprise Linux 4 and 5 by a patch included in RHSA-2010:0519.
Created libtiff tracking bugs for this issue Affects: fedora-all [bug 696204]
So far as I can tell, this is not only not a security issue, it's not a bug at all. That fax2ps.c code is exactly the same upstream in 3.9.4 and 3.9.5 except for a gratuitous change in the spelling of the error message. It looks to me like the submitted patch was entirely reverted by Bob Friesenhahn per http://bugzilla.maptools.org/show_bug.cgi?id=2118#c6 IOW, the original proposed patch was just plain wrong and unnecessary.
I had the wrong upstream bug for this one. I fixed my above comment, but we already fixed this issue in RHSA-2010:0519. No further action is needed. Sorry for the confusion.