This version is patched for the above vulnerability using the patches from Debian. Please, fix the GLSA so that it doesn't trigger false positive, unfortunately it's still needed for man-pages-ja :(
Fixed in CVS by adding sys-apps/groff *>= 1.18.1.1 to unaffected.