Upstream has issued an advisory today (April 18): http://openwall.com/lists/oss-security/2017/04/18/2 The issue is fixed in 2.2. Mageia 5 is also affected.
CC: (none) => geiger.david68210Whiteboard: (none) => MGA5TOO
URL: (none) => https://security-tracker.debian.org/tracker/CVE-2017-5661
Ubuntu has issued an advisory for this on May 9: https://www.ubuntu.com/usn/usn-3281-1/
Fixed for Cauldron in fop-2.0-7.mga6.
Whiteboard: MGA5TOO => (none)Version: Cauldron => 5
We won't be fixing this type of package for Mageia 5.
Status: NEW => RESOLVEDResolution: (none) => OLD