Fedora has issued an advisory today (January 20): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TQVHB5NDIZBYQOOR27366WCAOCDOXUI3/ Mageia 8 may also be affected.
Status comment: (none) => Patch available from FedoraWhiteboard: (none) => MGA8TOO
Assigning this to SRPM packager MarcK.
Assignee: bugsquad => mageia
like fedora says, it is not very likely this will/can be exploited. As this is just a tool running on command line to automate compile of tex. It is not worth patching this for mga8.
checked mga8: no log4j; logback is used here.
Whiteboard: MGA8TOO => (none)
no need to fix this.
Resolution: (none) => WONTFIXStatus: NEW => RESOLVED