Candidate: CVE-2012-4563 PublicDate: 2012-11-20 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4563 http://www.openwall.com/lists/oss-security/2012/10/30 http://www.openwall.com/lists/oss-security/2012/10/31/1 Description: Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Ubuntu-Description: Notes: jdstrand> per upstream, 2.4 only jdstrand> this is a duplicate of CVE-2012-5920 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=691900 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_gwt: upstream_gwt: released (2.5) hardy_gwt: DNE lucid_gwt: not-affected (1.6.4-0ubuntu5) oneiric_gwt: not-affected (1.6.4-1ubuntu2) precise_gwt: DNE quantal_gwt: ignored (reached end-of-life) raring_gwt: ignored (reached end-of-life) saucy_gwt: DNE trusty_gwt: DNE trusty/esm_gwt: DNE devel_gwt: DNE