Ubuntu has issued an advisory on May 6:
Mageia 7 is also affected.
Hi, thanks for reporting this.
As there is no maintainer for this package I added the committers in CC.
(Please set the status to 'assigned' if you are working on it)
geiger.david68210, olav, ouaurelien
Also the previous update (Bug 28454) introduced a regression, fixed here:
Fedora has issued an advisory for this on March 20:
The issue is fixed upstream in 0.3.1.
Fixed upstream in 0.3.1
Done for mga8 and mga7!
Fixed upstream in 0.3.1 =>
MGA7-64 Plasma on Lenovo B50
An installation snag: wwhen in MCC first selecting libgnome-autoar-gir0.1-0.3.1-1.mga7, MCC complains on missing libgnome-autoar0_0-0.3.1-1.mga7.
First selectng the latter, then the former, all is OK. Is this a dependency missing???
# urpmq --whatrequires lib64gnome-autoar0_0
and some more, installed gnome-recipes and run it as
$ strace -o lib64gnomeautoar.txt gnome-recipes
Look at one recipe, open the dialogue for a new recipe, close .
Checked the trace, find reference to te library, so seems to work OK.
I leave it to the higher powers whether this update can go, or the dependency needs mending. I will not object the OK.
@Herman with regard to comment 6.
I installed the three packages manually (one was already installed) without any problem so I think you can give this the OK - installed serially with libgnome-autoar0_0 first. (I have not tried updating yet)
Treading on your toes to have a look at the PoC.
If I understand this correctly the issue was not fully fixed by the first patch and needed further treatment.
Downloaded the linktotmp.tar file.
Ran nautilus to extract the contents of the tar file. gtar reported an error, no such file /tmp/foo, but a symbolic link was created pointing to /tmp.
$ unlink tmplink
Ran the extraction test on the poc file, which did exactly as before and created the tmplink symbolic link to /tmp and no /tmp/foo file. This may be the required behaviour - I have not quite worked it out yet. If it is then the issue is fixed.
Anyway you should go ahead and OK the update Herman.