please (aka pleaser) through version 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.) https://gitlab.com/edneville/please/-/merge_requests/69#note_1594254575 https://gitlab.com/edneville/please/-/issues/13 https://rustsec.org/advisories/RUSTSEC-2023-0066.html https://github.com/rustsec/advisory-db/pull/1798
Created rust-pleaser tracking bugs for this issue: Affects: epel-all [bug 2245339] Affects: fedora-all [bug 2245340]