A crafted SVG file could have caused information disclosure or denial of service by using external entitity expansion (XXE). This is a potentially incompatible change; however usually SVG files do not rely on XXE (CVE-2016-9181).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0151.json"