Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 351626 (CVE-2010-4647) - <dev-util/eclipse-sdk-3.6.2: multiple XSS vulnerabilities (CVE-2010-4647)
Summary: <dev-util/eclipse-sdk-3.6.2: multiple XSS vulnerabilities (CVE-2010-4647)
Status: RESOLVED FIXED
Alias: CVE-2010-4647
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor with 1 vote (vote)
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: B4? [noglsa]
Keywords:
Depends on: 325271
Blocks:
  Show dependency tree
 
Reported: 2011-01-14 07:20 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2015-05-24 08:19 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-01-14 07:20:24 UTC
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4647
Comment 1 Anton Bolshakov 2011-06-16 13:56:39 UTC
I found a working copy of the 3.6.2 ebuild in the belak overlay:
https://bitbucket.org/belak/belak.gentoo

you might want to have a look at it.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:36:42 UTC
CVE-2010-4647 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4647):
  Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web
  application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote
  attackers to inject arbitrary web script or HTML via the query string to (1)
  help/index.jsp or (2) help/advanced/content.jsp.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 21:37:42 UTC
@maintainers: can we clean <eclipse*-3.6.2? This would leave us with the 3.7 and 4.2 branches. Will clean in 30 days if no response is given.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-08-27 02:55:22 UTC
All dev-util/eclipse-sdk versions are hardmasked in tree. Closing bug noglsa.
Comment 5 genbug 2015-05-24 07:49:57 UTC
equery list -p eclipse-sdk
 dev-util/eclipse-sdk-3.5.1-r1:3.5

man, this is years old. Yet another orphaned package?
Comment 6 James Le Cuirot gentoo-dev 2015-05-24 08:19:12 UTC
(In reply to genbug from comment #5)
> man, this is years old. Yet another orphaned package?

It's one of the hardest of all Java packages to build. Are you going to maintain it?