← Back

CVE-2012-3489

nvd nist
Published: Oct 3, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.

Affected (22)

Show all products
1 product
Postgresql
1 product
Opensuse
1 product
Mac Os X Server
1 product
Ubuntu Linux
1 product
Debian Linux
4 products
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Workstation
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 8.3.0 to 8.3.20
From 8.4.0 to 8.4.13
From 9.0.0 to 9.0.9
From 9.1.0 to 9.1.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 11.4
Version 12.1
Version 12.2
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Apple
From 10.7.0 to 10.7.5
Version 10.6.8
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 11.04
Version 11.10
Version 12.04
Version 8.04
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration F
7 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 5.0
Version 6.0
Version 6.3
Redhat
Version 5.0
Version 6.0
Redhat
Version 5.0
Version 6.0

References (42)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release Notes
Source: secalert@redhat.com
Release NotesVendor Advisory
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchRelease Notes

Timeline

No history available yet.