CVE Vulnerabilities

CVE-2012-3488

Published: Oct 03, 2012 | Modified: Dec 08, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 9.1.4 9.1.4
Postgresql Postgresql 9.1 9.1
Postgresql Postgresql 9.1.2 9.1.2
Postgresql Postgresql 9.1.3 9.1.3
Postgresql Postgresql 9.1.1 9.1.1

References