CVE Database
/

CVE-2012-3489

Back to search

CVE-2012-3489

Published: Oct 3, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2012:1263
vendor-advisory
x_refsource_REDHAT
55074
vdb-entry
x_refsource_BID
MDVSA-2012:139
vendor-advisory
x_refsource_MANDRIVA
USN-1542-1
vendor-advisory
x_refsource_UBUNTU
50718
third-party-advisory
x_refsource_SECUNIA
50635
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2013-03-14-1
vendor-advisory
x_refsource_APPLE
50946
third-party-advisory
x_refsource_SECUNIA
DSA-2534
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2012:1251
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:1288
vendor-advisory
x_refsource_SUSE
50859
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2012:1299
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now