Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.870642
Categoría:Red Hat Local Security Checks
Título:RedHat Update for eclipse RHSA-2011:0568-01
Resumen:The remote host is missing an update for the 'eclipse'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'eclipse'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The Eclipse software development environment provides a set of tools for
C/C++ and Java development.

A cross-site scripting (XSS) flaw was found in the Eclipse Help Contents
web application. An attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted Eclipse Help URL. (CVE-2010-4647)

The following Eclipse packages have been upgraded to the versions found in
the official upstream Eclipse Helios SR1 release, providing a number of
bug fixes and enhancements over the previous versions:

* eclipse to 3.6.1. (BZ#656329)

* eclipse-cdt to 7.0.1. (BZ#656333)

* eclipse-birt to 2.6.0. (BZ#656391)

* eclipse-emf to 2.6.0. (BZ#656344)

* eclipse-gef to 3.6.1. (BZ#656347)

* eclipse-mylyn to 3.4.2. (BZ#656337)

* eclipse-rse to 3.2. (BZ#656338)

* eclipse-dtp to 1.8.1. (BZ#656397)

* eclipse-changelog to 2.7.0. (BZ#669499)

* eclipse-valgrind to 0.6.1. (BZ#669460)

* eclipse-callgraph to 0.6.1. (BZ#669462)

* eclipse-oprofile to 0.6.1. (BZ#670228)

* eclipse-linuxprofilingframework to 0.6.1. (BZ#669461)

In addition, the following updates were made to the dependencies of the
Eclipse packages above:

* icu4j to 4.2.1. (BZ#656342)

* sat4j to 2.2.0. (BZ#661842)

* objectweb-asm to 3.2. (BZ#664019)

* jetty-eclipse to 6.1.24. (BZ#661845)

This update includes numerous upstream bug fixes and enhancements, such as:

* The Eclipse IDE and Java Development Tools (JDT):

- - projects and folders can filter out resources in the workspace.

- - new virtual folder and linked files support.

- - the full set of UNIX file permissions is now supported.

- - addition of the stop button to cancel long-running wizard tasks.

- - Java editor now shows multiple quick-fixes via problem hover.

- - new support for running JUnit version 4 tests.

- - over 200 upstream bug fixes.

* The Eclipse C/C++ Development Tooling (CDT):

- - new Codan framework has been added for static code analysis.

- - refactoring improvements such as stored refactoring history.

- - compile and build errors now highlighted in the build console.

- - switch to the new DSF debugger framework.

- - new template view support.

- - over 600 upstream bug fixes.

This update also fixes the following bugs:

* Incorrect URIs for GNU Tools in the 'Help Contents' window have been
fixed. (BZ#622713)

* The profiling of binaries did not work if an Eclipse project was not in
an Eclipse workspace. This up ...

Description truncated, please see the referenced URL(s) for more information.

Affected Software/OS:
eclipse on Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-4647
FEDORA-2010-18990
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052532.html
FEDORA-2010-19006
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052554.html
MDVSA-2011:032
http://www.mandriva.com/security/advisories?name=MDVSA-2011:032
RHSA-2011:0568
http://www.redhat.com/support/errata/RHSA-2011-0568.html
[oss-security] 20110106 CVE Request: Eclipse IDE Version: 3.6.1 | Help Server Local Cross Site Scripting (XSS)
http://openwall.com/lists/oss-security/2011/01/06/7
[oss-security] 20110106 Re: CVE Request: Eclipse IDE Version: 3.6.1 | Help Server Local Cross Site Scripting (XSS)
http://openwall.com/lists/oss-security/2011/01/06/16
eclipseide-querystring-xss(64833)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64833
http://yehg.net/lab/pr0js/advisories/eclipse/%5Beclipse_help_server%5D_cross_site_scripting
https://bugs.eclipse.org/bugs/show_bug.cgi?id=329582
CopyrightCopyright (C) 2012 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.