Fedora has issued an advisory on January 7: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/ The issues are fixed upstream in 2.34.
Hi, thanks for reporting this. Assigned to the package maintainer. (Please set the status to 'assigned' if you are working on it)
Assignee: bugsquad => basesystemCC: (none) => ouaurelien, tmbCVE: (none) => CVE-2020-3549[3-6]
Depends on: (none) => 28305
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Status: NEW => RESOLVEDResolution: (none) => OLD