Debian has issued an advisory on February 9: https://www.debian.org/security/2018/dsa-4109 From the Debian bug, it sounds like it was fixed upstream in 1.6.1. We dropped this package after Mageia 5 and it's not worth fixing in Mageia 5 now (nothing appears to use it). Filing this bug just for informational purposes.
Closing.
Resolution: (none) => OLDStatus: NEW => RESOLVED