Upstream has issued an advisory today (April 18): http://openwall.com/lists/oss-security/2017/04/18/1 The issue is fixed in 1.9. Mageia 5 is also affected.
Whiteboard: (none) => MGA5TOOCC: (none) => geiger.david68210
URL: (none) => https://security-tracker.debian.org/tracker/CVE-2017-5662CVE: (none) => CVE-2017-5662
Fedora has issued an advisory for this today (May 9): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KPDLOK2DRJD3FVKIONDRJWLQNFR4MNWA/
Fixed in cauldron
Whiteboard: MGA5TOO => (none)Version: Cauldron => 5
We won't be fixing this type of package for Mageia 5.
Status: NEW => RESOLVEDResolution: (none) => OLD