CVE Vulnerabilities

CVE-2012-3488

Published: Oct 03, 2012 | Modified: Dec 08, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
3.8 MODERATE
AV:A/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 9.1 (including) 9.1 (including)
Postgresql Postgresql 9.1.1 (including) 9.1.1 (including)
Postgresql Postgresql 9.1.2 (including) 9.1.2 (including)
Postgresql Postgresql 9.1.3 (including) 9.1.3 (including)
Postgresql Postgresql 9.1.4 (including) 9.1.4 (including)
Red Hat Enterprise Linux 5 RedHat postgresql84-0:8.4.13-1.el5_8 *
Red Hat Enterprise Linux 5 RedHat postgresql-0:8.1.23-6.el5_8 *
Red Hat Enterprise Linux 6 RedHat postgresql-0:8.4.13-1.el6_3 *
Postgresql-8.2 Ubuntu hardy *
Postgresql-8.3 Ubuntu hardy *
Postgresql-8.4 Ubuntu lucid *
Postgresql-8.4 Ubuntu natty *
Postgresql-8.4 Ubuntu oneiric *
Postgresql-8.4 Ubuntu precise *
Postgresql-9.1 Ubuntu oneiric *
Postgresql-9.1 Ubuntu precise *
Postgresql-9.1 Ubuntu upstream *

References