CVE-2017-0366 — Improper Input Validation in Mediawiki
Severity
5.4MEDIUMNVD
EPSS
0.4%
top 40.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 14
Description
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5
Affected Packages4 packages
Also affects: Debian Linux 7.0
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
3Bugzilla▶
CVE-2017-0366 mediawiki: SVG filter evasion using default attribute values in DTD declaration↗2018-04-20
Bugzilla▶
CVE-2017-0362 CVE-2017-0364 CVE-2017-0366 CVE-2017-0370 mediawiki123: various flaws [epel-7]↗2018-04-19
Bugzilla▶
CVE-2017-2862 gdk-pixbuf2: Heap overflow in the gdk_pixbuf__jpeg_image_load_increment function↗2017-09-06