CVE Vulnerabilities

CVE-2012-3488

Published: Oct 03, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
3.8 MODERATE
AV:A/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql9.1 (including)9.1 (including)
PostgresqlPostgresql9.1.1 (including)9.1.1 (including)
PostgresqlPostgresql9.1.2 (including)9.1.2 (including)
PostgresqlPostgresql9.1.3 (including)9.1.3 (including)
PostgresqlPostgresql9.1.4 (including)9.1.4 (including)
Red Hat Enterprise Linux 5RedHatpostgresql84-0:8.4.13-1.el5_8*
Red Hat Enterprise Linux 5RedHatpostgresql-0:8.1.23-6.el5_8*
Red Hat Enterprise Linux 6RedHatpostgresql-0:8.4.13-1.el6_3*
Postgresql-8.2Ubuntuhardy*
Postgresql-8.3Ubuntuhardy*
Postgresql-8.4Ubuntulucid*
Postgresql-8.4Ubuntunatty*
Postgresql-8.4Ubuntuoneiric*
Postgresql-8.4Ubuntuprecise*
Postgresql-9.1Ubuntuoneiric*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntuupstream*

References