It was discovered that Puppet incorrectly handled permissions when unpacking certain tarballs. A local user could possibly use this issue to execute arbitrary code (CVE-2017-10689).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0199.json"