MilkyTracker through version 1.01 is vulnerable to multiple issues in various module loaders that could potentially lead to remote code execution. Upstream Issue: https://github.com/milkytracker/MilkyTracker/issues/35 Upstream Patch: https://github.com/milkytracker/MilkyTracker/commit/6f7922616f31e5ceddd6f346cfc7f5d61a2f7683
Created milkytracker tracking bugs for this issue: Affects: fedora-all [bug 1545502]
This should now be fixed in git for f26, f27 and master. Updates for F26 and F27 are at https://bodhi.fedoraproject.org/updates/FEDORA-2018-2331a462fb https://bodhi.fedoraproject.org/updates/FEDORA-2018-7d90e269a4 In the RPM package changelog I accidentally had inserted an incorrect upstream issue number (15 instead of 35). When I noticed this the packages were already pushed and built.
milkytracker-1.01.00-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.
ARRAY(0x558ebdb04e08)