openSUSE has issued an advisory on April 4: https://lists.opensuse.org/opensuse-updates/2017-04/msg00006.html There may also be a security-relevant post-1.4.2 commit, according to: https://bugzilla.suse.com/show_bug.cgi?id=1029595
Fixed in 1.4.2 (freeze push asked) with relevant patches added for the after commit fixes. Thanks, Cheers, Chris. PS: reopen if needed
Status: NEW => RESOLVEDResolution: (none) => FIXED