6.5
CVE-2012-3489
- EPSS 3.06%
- Veröffentlicht 03.10.2012 21:55:00
- Zuletzt bearbeitet 16.06.2026 23:43:19
- Erkennungen
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 8.3.0 < 8.3.20
Postgresql ≫ Postgresql Version >= 8.4.0 < 8.4.13
Postgresql ≫ Postgresql Version >= 9.0.0 < 9.0.9
Postgresql ≫ Postgresql Version >= 9.1.0 < 9.1.5
Apple ≫ macOS X Server Version >= 10.7.0 <= 10.7.5
Apple ≫ macOS X Server Version 10.6.8
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Debian ≫ Debian Linux Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.3
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.06% | 0.859 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html
http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html
http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html
http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html
http://secunia.com/advisories/50718
http://www.postgresql.org/support/security/
http://secunia.com/advisories/50859
http://rhn.redhat.com/errata/RHSA-2012-1263.html
http://secunia.com/advisories/50635
http://secunia.com/advisories/50946
http://www.debian.org/security/2012/dsa-2534
http://www.mandriva.com/security/advisories?name=MDVSA-2012:139
http://www.postgresql.org/about/news/1407/
http://www.postgresql.org/docs/8.3/static/release-8-3-20.html
http://www.postgresql.org/docs/8.4/static/release-8-4-13.html
http://www.postgresql.org/docs/9.0/static/release-9-0-9.html
http://www.postgresql.org/docs/9.1/static/release-9-1-5.html
http://www.ubuntu.com/usn/USN-1542-1
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2
http://www.securityfocus.com/bid/55074
https://bugzilla.redhat.com/show_bug.cgi?id=849173