he xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
21 Nov 2024, 01:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html - Mailing List | |
| References | () http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html - Mailing List | |
| References | () http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html - Mailing List | |
| References | () http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html - Mailing List | |
| References | () http://rhn.redhat.com/errata/RHSA-2012-1263.html - Third Party Advisory | |
| References | () http://secunia.com/advisories/50635 - Broken Link | |
| References | () http://secunia.com/advisories/50718 - Broken Link | |
| References | () http://secunia.com/advisories/50859 - Broken Link | |
| References | () http://secunia.com/advisories/50946 - Broken Link | |
| References | () http://www.debian.org/security/2012/dsa-2534 - Mailing List | |
| References | () http://www.mandriva.com/security/advisories?name=MDVSA-2012:139 - Broken Link | |
| References | () http://www.postgresql.org/about/news/1407/ - Vendor Advisory | |
| References | () http://www.postgresql.org/docs/8.3/static/release-8-3-20.html - Release Notes | |
| References | () http://www.postgresql.org/docs/8.4/static/release-8-4-13.html - Release Notes | |
| References | () http://www.postgresql.org/docs/9.0/static/release-9-0-9.html - Release Notes | |
| References | () http://www.postgresql.org/docs/9.1/static/release-9-1-5.html - Release Notes | |
| References | () http://www.postgresql.org/support/security/ - Release Notes, Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/55074 - Broken Link, Third Party Advisory, VDB Entry | |
| References | () http://www.ubuntu.com/usn/USN-1542-1 - Third Party Advisory | |
| References | () https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=849173 - Issue Tracking, Patch, Release Notes |
Published : 2012-10-03 21:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-3489
Mitre link : CVE-2012-3489
CVE.ORG link : CVE-2012-3489
JSON object : View
Improper Restriction of XML External Entity Reference