KDE has issued an advisory on February 27: https://www.kde.org/info/security/advisory-20170227-1.txt The issue will be fixed in KDE Applications 16.12.3, but Mageia 5 is also affected.
It looks like KTNEFMain::extractTo() in kdepim-4.14.10/ktnef/ktnefmain.cpp *might* be affected, but the code is quite different. We won't be able to backport a fix for this for Mageia 5.
Resolution: (none) => OLDStatus: NEW => RESOLVED