Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
I'll look into fixing this issue this Saturday if no one beats me to it.
I'm fairly sure this is already fixed in 4.4.0. Several such fixes for "bugs" were in that release, which I already packaged for Rawhide. So it should just be as simple as pulling that into the desired release branch. As I don't have a desktop Fedora install anymore I can't very well test those builds so I refrain from pulling new releases into existing Fedora versions. But a merge from rawhide with a build and Bodhi fix ought to accomplish what you need.
I'm a little rusty on what Fedora's policies are around pulling new versions into existing releases (most of my work is in Debian/Ubuntu where the process is "backport the patch", but I know Fedora operates somewhat differently). That sounds like it will probably work though. Thanks for the tip!
I embarrassingly forgot this over the weekend. I've gotten a packaging VM set up again, I'll try to remember to do this Monday morning.