Upstream has issued an advisory today (July 15): http://openwall.com/lists/oss-security/2016/07/15/3 The issue is fixed in 0.13.1. Mageia 5 is not affected.
CC: (none) => geiger.david68210, mageia
CVE: (none) => CVE-2016-4467
Fixed in cauldron
Status: NEW => RESOLVEDResolution: (none) => FIXED