libbsd 0.8.1 and earlier contains a buffer overflow in the function fgetwln(). An if checks if it is necessary to reallocate memory in the target buffer. However this check is off by one, therefore an out of bounds write happens. (backtick) characters in a print job. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2090