CVE-2017-0366Improper Input Validation in Mediawiki

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 40.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 14

Description

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

debiandebian/mediawiki< mediawiki 1:1.27.2-1 (bookworm)
NVDmediawiki/mediawiki1.27.01.27.2+2
Debianmediawiki/mediawiki< 1:1.27.2-1+3
CVEListV5mediawiki/mediawikin/a

Also affects: Debian Linux 7.0

🔴Vulnerability Details

2
GHSA
GHSA-3cfx-qf53-8h6m: Mediawiki before 12022-05-14
OSV
CVE-2017-0366: Mediawiki before 12018-04-13

📋Vendor Advisories

2
Debian
CVE-2017-0366: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG...2017
Red Hat
mediawiki: SVG filter evasion using default attribute values in DTD declaration2016-11-27

💬Community

3
Bugzilla
CVE-2017-0366 mediawiki: SVG filter evasion using default attribute values in DTD declaration2018-04-20
Bugzilla
CVE-2017-0362 CVE-2017-0364 CVE-2017-0366 CVE-2017-0370 mediawiki123: various flaws [epel-7]2018-04-19
Bugzilla
CVE-2017-2862 gdk-pixbuf2: Heap overflow in the gdk_pixbuf__jpeg_image_load_increment function2017-09-06
CVE-2017-0366 — Improper Input Validation in Mediawiki | cvebase