CVE-2012-3489
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or…
Does this matter?
Lower severity and a low EPSS score (3.06%). Track it; it rarely justifies an emergency change on its own.
Description
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.06% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- postgresql/postgresql · opensuse/opensuse · apple/mac os x server · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2012-1263.htmlThird Party Advisory
- http://secunia.com/advisories/50635Broken Link
- http://secunia.com/advisories/50718Broken Link
- http://secunia.com/advisories/50859Broken Link
- http://secunia.com/advisories/50946Broken Link
- http://www.debian.org/security/2012/dsa-2534Mailing List
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:139Broken Link
- http://www.postgresql.org/about/news/1407/Vendor Advisory
- http://www.postgresql.org/docs/8.3/static/release-8-3-20.htmlRelease Notes
- http://www.postgresql.org/docs/8.4/static/release-8-4-13.htmlRelease Notes
- http://www.postgresql.org/docs/9.0/static/release-9-0-9.htmlRelease Notes
- http://www.postgresql.org/docs/9.1/static/release-9-1-5.htmlRelease Notes
- http://www.postgresql.org/support/security/Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/55074Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1542-1Third Party Advisory
- https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=849173Issue Tracking, Patch, Release Notes
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2012-1263.htmlThird Party Advisory
- http://secunia.com/advisories/50635Broken Link
- http://secunia.com/advisories/50718Broken Link
- http://secunia.com/advisories/50859Broken Link
- http://secunia.com/advisories/50946Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.