Fedora has issued an advisory on December 28: https://lists.fedoraproject.org/pipermail/package-announce/2014-May/132654.html I'm not sure I agree with this CVE. In the case of Mageia, we are "affected" as the package ships the directory with 755 permissions, but I would think that anyone that *cares* about such would be running in msec secure mode, which would change it to 700. I'm open to other opinions. Reproducible: Steps to Reproduce:
CC: (none) => mageia
Last year there were a lot of related CVEs that I just ignored.
CC: (none) => oe
Thanks Oden. I probably did too. I'll close this as WONTFIX.
Status: NEW => RESOLVEDResolution: (none) => WONTFIX