CVE-2017-0367: Debian Linux

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Mediawiki Mediawiki: from 1.27.0, before 1.27.2 (fixed in 1.27.2); from 1.28.0, before 1.28.1 (fixed in 1.28.1)

Published 2018-04-13. Last modified 2026-06-17.