Fedora has issued an advisory today (December 3): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/AJKJFPCG3MZ3P2ZHGEX43X327IM4YL6K/ It's not clear which older versions may be affected, but the upstream bug has a PoC. The issue was fixed in 1.1.5.
Assigning to the registered maintainer.
CC: (none) => marja11Assignee: bugsquad => geiger.david68210
Ubuntu has yet to make an assessment of this for 1.0.x: https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-9847.html Debian says it is probably affected: https://security-tracker.debian.org/tracker/CVE-2017-9847 Looking at the code, I disagree, I think 1.0.x is fine. I'll reopen if someone ships and update for it.
Version: 6 => CauldronResolution: (none) => FIXEDStatus: NEW => RESOLVED