Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 351626 (CVE-2010-4647)

Summary: <dev-util/eclipse-sdk-3.6.2: multiple XSS vulnerabilities (CVE-2010-4647)
Product: Gentoo Security Reporter: Paweł Hajdan, Jr. (RETIRED) <phajdan.jr>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: bugsgentoo, java, kripton
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4647
Whiteboard: B4? [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 325271    
Bug Blocks:    

Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-01-14 07:20:24 UTC
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4647
Comment 1 Anton Bolshakov 2011-06-16 13:56:39 UTC
I found a working copy of the 3.6.2 ebuild in the belak overlay:
https://bitbucket.org/belak/belak.gentoo

you might want to have a look at it.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:36:42 UTC
CVE-2010-4647 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4647):
  Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web
  application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote
  attackers to inject arbitrary web script or HTML via the query string to (1)
  help/index.jsp or (2) help/advanced/content.jsp.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 21:37:42 UTC
@maintainers: can we clean <eclipse*-3.6.2? This would leave us with the 3.7 and 4.2 branches. Will clean in 30 days if no response is given.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-08-27 02:55:22 UTC
All dev-util/eclipse-sdk versions are hardmasked in tree. Closing bug noglsa.
Comment 5 genbug 2015-05-24 07:49:57 UTC
equery list -p eclipse-sdk
 dev-util/eclipse-sdk-3.5.1-r1:3.5

man, this is years old. Yet another orphaned package?
Comment 6 James Le Cuirot gentoo-dev 2015-05-24 08:19:12 UTC
(In reply to genbug from comment #5)
> man, this is years old. Yet another orphaned package?

It's one of the hardest of all Java packages to build. Are you going to maintain it?