CVE-2017-0366: Debian Linux

Medium severity, CVSS 5.4. EPSS: 1.3% chance of exploitation in the next 30 days.

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Mediawiki Mediawiki: from 1.23.0, up to and including 1.23.16; from 1.27.0, before 1.27.2 (fixed in 1.27.2); from 1.28.0, before 1.28.1 (fixed in 1.28.1)

Published 2018-04-13. Last modified 2026-06-17.