Upstream has issued an advisory on October 31: https://www.openwall.com/lists/oss-security/2018/10/31/8 The issue is fixed upstream in 1.2.46. Mageia 6 is also affected.
Whiteboard: (none) => MGA6TOO
Assigning to the registered maintainer.
Assignee: bugsquad => shlomifCC: (none) => marja11
apache-mod_jk-1.2.46-1.mga7 uploaded for Cauldron by Shlomi.
Whiteboard: MGA6TOO => (none)Version: Cauldron => 6
Debian has issued an advisory for this on December 20: https://www.debian.org/security/2018/dsa-4357
Mageia 6 is EOL.
Status: NEW => RESOLVEDResolution: (none) => OLDCC: (none) => mrambo