Oval Definition:oval:com.ubuntu.precise:def:20123489000
Revision Date:2012-10-03Version:1
Title:CVE-2012-3489 on Ubuntu 12.04 LTS (precise) - medium.
Description:The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-3489
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'postgresql-8.4' package in precise was vulnerable but has been fixed (note: '8.4.22-0ubuntu0.12.04').
  • OR The 'postgresql-9.1' package in precise was vulnerable but has been fixed (note: '9.1.5-0ubuntu12.04').
  • BACK