A flaw was found in units. units_cur doesn't sanitize downloaded data. This allows a maliciously intended server to execute arbitrary code remotely on the client (rhbz#1598913).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2019-0007.json"