CVE-2012-3488
Publication date 17 August 2012
Last updated 24 July 2024
Ubuntu priority
The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.
Status
Package | Ubuntu Release | Status |
---|---|---|
postgresql-8.2 | ||
14.04 LTS trusty | Not in release | |
postgresql-8.3 | ||
14.04 LTS trusty | Not in release | |
postgresql-8.4 | ||
14.04 LTS trusty | Not in release | |
postgresql-9.1 | ||
14.04 LTS trusty | Not in release | |
References
Related Ubuntu Security Notices (USN)
- USN-1542-1
- PostgreSQL vulnerabilities
- 21 August 2012