CVE-2012-3489
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before… (CVE-2012-3489)
Description
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Metrics
Affected operating systems
linux
debian / debian_linux6.0
linux
redhat / enterprise_linux_desktop5.0
linux
redhat / enterprise_linux_desktop6.0
linux
redhat / enterprise_linux_eus6.3
linux
redhat / enterprise_linux_server5.0
linux
redhat / enterprise_linux_server6.0
linux
redhat / enterprise_linux_workstation5.0
linux
redhat / enterprise_linux_workstation6.0
linux
canonical / ubuntu_linux10.04
linux
canonical / ubuntu_linux11.04
linux
canonical / ubuntu_linux11.10
linux
canonical / ubuntu_linux12.04
linux
canonical / ubuntu_linux8.04
macos
apple / mac_os_x_server
macos
apple / mac_os_x_server10.6.8
os
opensuse / opensuse11.4
os
opensuse / opensuse12.1
os
opensuse / opensuse12.2
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
postgresql
postgresql8.3.0 – 8.3.20
postgresql
postgresql8.4.0 – 8.4.13
postgresql
postgresql9.0.0 – 9.0.9
postgresql
postgresql9.1.0 – 9.1.5
References & sources
- http://rhn.redhat.com/errata/RHSA-2012-1263.htmlvendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/55074vdb-entryx_refsource_BID
- http://www.postgresql.org/docs/9.0/static/release-9-0-9.htmlx_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:139vendor-advisoryx_refsource_MANDRIVA
- http://www.ubuntu.com/usn/USN-1542-1vendor-advisoryx_refsource_UBUNTU
- http://secunia.com/advisories/50718third-party-advisoryx_refsource_SECUNIA
- http://www.postgresql.org/docs/9.1/static/release-9-1-5.htmlx_refsource_CONFIRM
- https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2x_refsource_CONFIRM
- http://www.postgresql.org/docs/8.4/static/release-8-4-13.htmlx_refsource_CONFIRM
- http://www.postgresql.org/docs/8.3/static/release-8-3-20.htmlx_refsource_CONFIRM
- http://www.postgresql.org/about/news/1407/x_refsource_CONFIRM
- http://secunia.com/advisories/50635third-party-advisoryx_refsource_SECUNIA
- http://www.postgresql.org/support/security/x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlvendor-advisoryx_refsource_APPLE
- http://secunia.com/advisories/50946third-party-advisoryx_refsource_SECUNIA
- https://bugzilla.redhat.com/show_bug.cgi?id=849173x_refsource_CONFIRM
- http://www.debian.org/security/2012/dsa-2534vendor-advisoryx_refsource_DEBIAN
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlvendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/50859third-party-advisoryx_refsource_SECUNIA