Oval Definition:oval:org.mitre.oval:def:23579
Revision Date:2014-05-26Version:22
Title:ELSA-2012:1263: postgresql and postgresql84 security update (Moderate)
Description:The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-3488
CVE-2012-3489
ELSA-2012:1263-01
Platform(s):Oracle Linux 5
Oracle Linux 6
Product(s):postgresql
postgresql84
Definition Synopsis
  • rpm test
  • Oracle Linux 5.x
  • AND rpm test
  • postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-server is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-docs is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84 is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-test is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-contrib is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-tcl is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-plpython is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-plperl is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-python is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-devel is earlier than 0:8.4.13-1.el5_8
  • OR postgresql84-libs is earlier than 0:8.4.13-1.el5_8
  • OR rpm test
  • Oracle Linux 6.x
  • AND rpm test
  • postgresql is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-server is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-devel is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-libs is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-pltcl is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-plpython is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-docs is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-test is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-plperl is earlier than 0:8.4.13-1.el6_3
  • OR postgresql-contrib is earlier than 0:8.4.13-1.el6_3
  • BACK