New groff packages have been made available that fix an overflow in groff. If the printing system running this is a security issue, it is recommended to update to the new, fixed packages.
Groff is a document formatting system. The groff preprocessor contains an exploitable buffer overflow. If groff can be invoked within the LPRng printing system, an attacker can gain rights as the "lp" user. Remote exploitation may be possible if lpd is running and is accessible remotely, and the attacker knows the name of the printer and spoolfile. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0003 to this issue. Thanks to zen-parse for bringing this bug to our attention.