http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5197 "Buffer overflow in the Mono.Math.BigInteger class in Mono allows context-dependent attackers to execute arbitrary code via unspecified vectors." Patch extracted from Debian's 1.2.2.1-1etch1 patchkit (attached) seems to apply to 1.2.5.1 in devel with some line offsets, I have done no further analysis.
Created attachment 248611 [details] Patch from Debian
Gentoo also has a patch, maybe a different one http://bugs.gentoo.org/show_bug.cgi?id=197067
mono-1.2.5.1-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Alex: I'd urge this a bit. When are f6 and f7 versions likely to hit the repositories? (I've noticed there was some issue with libs on 64 bit platforms..?)
mono-1.2.3-5.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Fedora updates: https://admin.fedoraproject.org/updates/F7/FEDORA-2007-3130 https://admin.fedoraproject.org/updates/F8/FEDORA-2007-2969