openSUSE has issued an advisory on December 8: https://lists.opensuse.org/opensuse-updates/2018-12/msg00028.html Mageia 6 is also affected.
Whiteboard: (none) => MGA6TOO
Pam has no registered maintainer, assuming it counts as a BaseSystem application so assigning to the Base System maintainers and CC'ing some committers. Please reassign to all packagers collectively if I'm wrong.
CC: (none) => makowski.mageia, marja11, thierry.vignaud, tmbAssignee: bugsquad => basesystem
Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO
Whiteboard: MGA7TOO, MGA6TOO => MGA7TOOCC: (none) => mageia
as explained here: https://security-tracker.debian.org/tracker/CVE-2018-17953 this CVE is introduced by a suse specific patch, so we are not affected
Status: NEW => RESOLVEDResolution: (none) => INVALID