Fedora Account System
Red Hat Associate
Red Hat Customer
MilkyTracker through version 1.01 is vulnerable to multiple issues in various module loaders that could potentially lead to remote code execution. Upstream Issue: https://github.com/milkytracker/MilkyTracker/issues/35 Upstream Patch: https://github.com/milkytracker/MilkyTracker/commit/6f7922616f31e5ceddd6f346cfc7f5d61a2f7683
Created milkytracker tracking bugs for this issue: Affects: fedora-all [bug 1545502]
This should now be fixed in git for f26, f27 and master. Updates for F26 and F27 are at https://bodhi.fedoraproject.org/updates/FEDORA-2018-2331a462fb https://bodhi.fedoraproject.org/updates/FEDORA-2018-7d90e269a4 In the RPM package changelog I accidentally had inserted an incorrect upstream issue number (15 instead of 35). When I noticed this the packages were already pushed and built.
milkytracker-1.01.00-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.
ARRAY(0x558ebdb04e08)