OpenSuSE has issued an advisory on December 27: http://lists.opensuse.org/opensuse-updates/2015-12/msg00117.html While technically this isn't a security issue for us due to the protected_symlinks feature in the kernel, it's a bug that should be fixed (at least in Cauldron). The maintainer can decide whether to issue a fix for Mageia 5. Reproducible: Steps to Reproduce:
Fixed in gummi-0.6.5-7.mga6.
Version: Cauldron => 5
CC: (none) => marja11Component: RPM Packages => SecurityQA Contact: (none) => security
Component: Security => RPM PackagesQA Contact: security => (none)
reassigning to the current gummi maintainer
Assignee: mitya => rverschelde
We don't need to fix this for Mageia 5.
Status: NEW => RESOLVEDVersion: 5 => CauldronResolution: (none) => FIXED