CVE-2012-3489
Summary
| CVE | CVE-2012-3489 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-03 21:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-611 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| APPLE-SA-2013-03-14-1 OS X Mountain Lion v10.8.3 and Security Update 2013-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List |
| openSUSE-SU-2012:1299-1: moderate: postgresql: security and bugfix upgra | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| PostgreSQL: Security Update 2012-08-17 released | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| openSUSE-SU-2012:1251-1: moderate: postgresql, postgresql-libs | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Security Advisory SA50718 - SUSE update for postgresql and postgresql-libs - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| PostgreSQL: Documentation: 8.4: Release 8.4.13 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes |
| USN-1542-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-2534-1 postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List |
| openSUSE-SU-2012:1288-1: moderate: postgresql, postgresql-libs | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| PostgreSQL: Documentation: 9.0: Release 9.0.9 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes |
| PostgreSQL: Documentation: 9.1: Release 9.1.5 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes |
| PostgreSQL: Documentation: 8.3: Release 8.3.20 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Multiple vulnerabilities in PostgreSQL (Third Party Vulnerability Resolution Blog) | af854a3a-2127-422b-91ae-364da2661108 | blogs.oracle.com | Third Party Advisory |
| PostgreSQL 'xml_parse()' Function Arbitrary File Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Bug 849173 – CVE-2012-3489 postgresql: File disclosure through XXE in xmlparse by DTD validation | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Release Notes |
| Support / Security / Advisories / / MDVSA-2012:139 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Security Advisory SA50946 - Oracle Solaris PostgreSQL "xml_parse()" and "xslt_process()" Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Security Advisory SA50635 - Red Hat update for postgresql and postgresql84 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.