CVE-2012-3488
Summary
| CVE | CVE-2012-3488 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-03 21:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 8.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.19 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.0 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| APPLE-SA-2013-03-14-1 OS X Mountain Lion v10.8.3 and Security Update 2013-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| openSUSE-SU-2012:1299-1: moderate: postgresql: security and bugfix upgra | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| PostgreSQL: Security Update 2012-08-17 released | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| openSUSE-SU-2012:1251-1: moderate: postgresql, postgresql-libs | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA50718 - SUSE update for postgresql and postgresql-libs - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL: Documentation: 8.4: Release 8.4.13 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| USN-1542-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Advisory SA50636 - Red Hat update for postgresql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-2534-1 postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| openSUSE-SU-2012:1288-1: moderate: postgresql, postgresql-libs | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| PostgreSQL: Documentation: 9.0: Release 9.0.9 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| PostgreSQL: Documentation: 9.1: Release 9.1.5 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| PostgreSQL: Documentation: 8.3: Release 8.3.20 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Multiple vulnerabilities in PostgreSQL (Third Party Vulnerability Resolution Blog) | af854a3a-2127-422b-91ae-364da2661108 | blogs.oracle.com | |
| PostgreSQL 'xslt_process()' Function Arbitrary File Creation or Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Bug 849172 – CVE-2012-3488 postgresql (xml2 contrib module): XXE by applying XSL stylesheet to the document | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Support / Security / Advisories / / MDVSA-2012:139 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Advisory SA50946 - Oracle Solaris PostgreSQL "xml_parse()" and "xslt_process()" Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA50635 - Red Hat update for postgresql and postgresql84 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.