Description
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2534-1 | postgresql-8.4 security update |
Ubuntu USN |
USN-1542-1 | PostgreSQL vulnerabilities |
References
History
No history.
Subscriptions
Apple
Subscribe
Mac Os X Server
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Postgresql
Subscribe
Postgresql
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T20:05:12.659Z
Reserved: 2012-06-14T00:00:00.000Z
Link: CVE-2012-3489
No data.
Status : Deferred
Published: 2012-10-03T21:55:00.813
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-3489
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN