Fedora has issued an advisory on December 9: https://lists.fedoraproject.org/pipermail/package-announce/2015-December/173515.html I'm not sure how important any of these fixes are or if we should update the Mageia 5 package as well, I'll leave that to the maintainer to evaluate. The Cauldron package should be updated at the very least. Reproducible: Steps to Reproduce:
Two more issues fixed in 1.2.1 (1.2.2 fixes some regressions): http://openwall.com/lists/oss-security/2017/02/01/4 http://openwall.com/lists/oss-security/2017/02/01/5
Summary: pax-utils several security-related fixes in 1.1.4 => pax-utils several security-related fixes in 1.1.4 and 1.2.1
More issues fixed (with commit links): http://openwall.com/lists/oss-security/2017/02/04/2 http://openwall.com/lists/oss-security/2017/02/04/3 http://openwall.com/lists/oss-security/2017/02/04/4
Another issue that will be fixed in 1.2.3 (with commit links): http://openwall.com/lists/oss-security/2017/02/25/1
thierry some thoughs about this issue ?
CC: (none) => mageia
updated on cauldron
Status: NEW => RESOLVEDResolution: (none) => FIXED