|
|
| |
|
| |
postgresql: file disclosure
| Package(s): | postgresql |
CVE #(s): | CVE-2012-3488
CVE-2012-3489
|
| Created: | August 20, 2012 |
Updated: | September 28, 2012 |
| Description: |
From the postgresql advisory:
This security release fixes a vulnerability in the built-in XML
functionality, and a vulnerability in the XSLT functionality supplied by
the optional XML2 extension. Both vulnerabilities allow reading of
arbitrary files by any authenticated database user, and the XSLT
vulnerability allows writing files as well. The fixes cause limited
backwards compatibility issues. |
| Alerts: |
|
( Log in to post comments)
|
|
|