CVE-2012-3489
MEDIUMPostgresql < 8.3.20 - XXE
Title source: ruleDescription
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
References (21)
... and 1 more
Scores
CVSS v3
6.5
EPSS
0.0096
EPSS Percentile
76.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-611
Status
draft
Affected Products (19)
postgresql/postgresql
< 8.3.20
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
apple/mac_os_x_server
< 10.7.5
apple/mac_os_x_server
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
... and 4 more
Timeline
Published
Oct 03, 2012
Tracked Since
Feb 18, 2026