Mandriva Linux Security Advisory : eclipse (MDVSA-2011:032)

Medium Nessus Plugin ID 52041


The remote Mandriva Linux host is missing one or more security updates.


A vulnerability has been found and corrected in eclipse :

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp (CVE-2010-4647).

Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: products_id=490

The updated packages have been patched to correct this issue.


Update the affected packages.

Plugin Details

Severity: Medium

ID: 52041

File Name: mandriva_MDVSA-2011-032.nasl

Version: $Revision: 1.9 $

Type: local

Published: 2011/02/21

Modified: 2016/05/17

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:eclipse-ecj, p-cpe:/a:mandriva:linux:eclipse-jdt, p-cpe:/a:mandriva:linux:eclipse-pde, p-cpe:/a:mandriva:linux:eclipse-platform, p-cpe:/a:mandriva:linux:eclipse-rcp, p-cpe:/a:mandriva:linux:eclipse-swt, cpe:/o:mandriva:linux:2009.0, cpe:/o:mandriva:linux:2010.0, cpe:/o:mandriva:linux:2010.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/02/20

Reference Information

CVE: CVE-2010-4647

BID: 44883

MDVSA: 2011:032