Fedora has issued an advisory today (April 17): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Z4KPDOHYXXLZC3SBQSGCQE5AOZCRTP6P/ The issue is fixed in 1.1.20. The upstream commit to fix it is linked from: https://bugzilla.redhat.com/show_bug.cgi?id=1441584 Mageia 5 is also affected.
Whiteboard: (none) => MGA5TOO
QA Contact: (none) => securityComponent: RPM Packages => Security
Whiteboard: MGA5TOO => (none)CC: (none) => mageia
Fixed in cauldron, and mga5 is not affected.
Resolution: (none) => FIXEDStatus: NEW => RESOLVED