CVE-2012-3489
published 2012-10-03CVE-2012-3489: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
3.06%
86.1th percentile
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | 10.7.0 – 10.7.5 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| postgresql | postgresql | >= 8.3.0 < 8.3.20 | 8.3.20 |
| postgresql | postgresql | >= 8.4.0 < 8.4.13 | 8.4.13 |
| postgresql | postgresql | >= 9.0.0 < 9.0.9 | 9.0.9 |
| postgresql | postgresql | >= 9.1.0 < 9.1.5 | 9.1.5 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fpq4-mcf9-c5w9: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8
ghsa_unreviewed·2022-05-17
CVE-2012-3489 [MEDIUM] CWE-20 GHSA-fpq4-mcf9-c5w9: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2012-08-21·CVSS 4.9
CVE-2012-3488 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL could allow unintended access to files over the network when
using the XML2 extension.
Peter Eisentraut discovered that the XSLT functionality in the optional
XML2 extension would allow unprivileged database users to both read and
write data with the privileges of the database server. (CVE-2012-3488)
Noah Misch and Tom Lane discovered that the XML functionality in the
optional XML2 extension would allow unprivileged database users to
read data with the privileges of the database server. (CVE-2012-3489)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. Due to upstream security policies, this update removes the ability
of xslt_process() to fetch documents or stylesheets from external URLs.
Ple
Red Hat
postgresql: File disclosure through XXE in xmlparse by DTD validation
vendor_redhat·2012-08-17·CVSS 6.5
CVE-2012-3489 [MEDIUM] postgresql: File disclosure through XXE in xmlparse by DTD validation
postgresql: File disclosure through XXE in xmlparse by DTD validation
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Package: postgresql (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3489 postgresql: File disclosure through XXE in xmlparse by DTD validation
bugzilla·2012-08-17·CVSS 6.5
CVE-2012-3489 [MEDIUM] CVE-2012-3489 postgresql: File disclosure through XXE in xmlparse by DTD validation
CVE-2012-3489 postgresql: File disclosure through XXE in xmlparse by DTD validation
An XML External Entities (XXE) attack was found in the way xmlparse routine, used for producing of xml data type value from character data, of PostgreSQL, an advanced Object-Relational database management system (DBMS), performed parsing of provided character data. An unprivileged database user could issue a specially-crafted SQL query to the PostgreSQL server that, when processed could lead to attacker's ability to read arbitrary system files, accessible with privileges of the user running the PostgreSQL server.
References:
[1] http://www.postgresql.org/docs/8.3/static/release-8-3-20.html
[2] http://www.postgresql.org/docs/9.0/static/release-9-0-9.html
[3] http://www.postgresql.org/docs/9.1/static/releas
Bugzilla
CVE-2012-3488 CVE-2012-3489 postgresql various flaws [fedora-all]
bugzilla·2012-08-17·CVSS 4.9
CVE-2012-3488 [MEDIUM] CVE-2012-3488 CVE-2012-3489 postgresql various flaws [fedora-all]
CVE-2012-3488 CVE-2012-3489 postgresql various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=8491
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1263.htmlhttp://secunia.com/advisories/50635http://secunia.com/advisories/50718http://secunia.com/advisories/50859http://secunia.com/advisories/50946http://www.debian.org/security/2012/dsa-2534http://www.mandriva.com/security/advisories?name=MDVSA-2012:139http://www.postgresql.org/about/news/1407/http://www.postgresql.org/docs/8.3/static/release-8-3-20.htmlhttp://www.postgresql.org/docs/8.4/static/release-8-4-13.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-9.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-5.htmlhttp://www.postgresql.org/support/security/http://www.securityfocus.com/bid/55074http://www.ubuntu.com/usn/USN-1542-1https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2https://bugzilla.redhat.com/show_bug.cgi?id=849173http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1263.htmlhttp://secunia.com/advisories/50635http://secunia.com/advisories/50718http://secunia.com/advisories/50859http://secunia.com/advisories/50946http://www.debian.org/security/2012/dsa-2534http://www.mandriva.com/security/advisories?name=MDVSA-2012:139http://www.postgresql.org/about/news/1407/http://www.postgresql.org/docs/8.3/static/release-8-3-20.htmlhttp://www.postgresql.org/docs/8.4/static/release-8-4-13.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-9.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-5.htmlhttp://www.postgresql.org/support/security/http://www.securityfocus.com/bid/55074http://www.ubuntu.com/usn/USN-1542-1https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2https://bugzilla.redhat.com/show_bug.cgi?id=849173
2012-10-03
Published