[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-30 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327696#comment-327696 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- Shouldn't the Apache Root POM not be

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-30 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327697#comment-327697 ] SebbASF commented on MJAVADOC-370: -- +1 Created https://issues.apache.org/jira/browse/MPOM-46

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327218#comment-327218 ] SebbASF commented on MJAVADOC-370: -- The property name seems odd: @Parameter(defaultValue =

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Olivier Lamy closed MJAVADOC-370. - Resolution: Fixed Fix Version/s: 2.9.1 Javadoc vulnerability (CVE-2013-1571 [1],

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327219#comment-327219 ] Olivier Lamy commented on MJAVADOC-370: --- @sebb good remark. I changed it. Thanks!

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327220#comment-327220 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- Hi, I just wanted to confirm that

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Olivier Lamy updated MJAVADOC-370: -- Attachment: (was: MJAVADOC-370.patch) Javadoc vulnerability (CVE-2013-1571 [1],

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Olivier Lamy updated MJAVADOC-370: -- Attachment: (was: MJAVADOC-370.patch) Javadoc vulnerability (CVE-2013-1571 [1],

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Olivier Lamy updated MJAVADOC-370: -- Attachment: (was: MJAVADOC-370.patch) Javadoc vulnerability (CVE-2013-1571 [1],

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-24 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327226#comment-327226 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- FYI, for ANT users I filed a similar

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327185#comment-327185 ] Uwe Schindler edited comment on MJAVADOC-370 at 6/23/13 5:34 AM: -

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327185#comment-327185 ] Uwe Schindler commented on MJAVADOC-370: Hi, I did some investigations on the tool as

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327186#comment-327186 ] Olivier Lamy commented on MJAVADOC-370: --- @Uwe maybe you could propose a fix here:

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327187#comment-327187 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- [~olamy]: For sure I can propose a

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327189#comment-327189 ] SebbASF commented on MJAVADOC-370: -- I agree that the Oracle tool is looking less and less useful

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327190#comment-327190 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- bq. I agree that the Oracle tool is

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327191#comment-327191 ] Olivier Lamy commented on MJAVADOC-370: --- make sense Javadoc vulnerability

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327192#comment-327192 ] SebbASF commented on MJAVADOC-370: -- The quickfix bug would still need to be considered for a

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327193#comment-327193 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- No official Javadoc tool before the

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327194#comment-327194 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- But I agree, you could aldo do the

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Uwe Schindler (ASF) updated MJAVADOC-370: - Attachment: MJAVADOC-370.patch Attached is my quick fix thats directly included

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327199#comment-327199 ] Uwe Schindler (ASF) edited comment on MJAVADOC-370 at 6/23/13 10:19 AM:

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327201#comment-327201 ] Uwe Schindler (ASF) commented on MJAVADOC-370: -- To conclude: - I tested with JDK

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Uwe Schindler (ASF) updated MJAVADOC-370: - Attachment: MJAVADOC-370.patch Slightly improved patch (removed the encoding null

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Uwe Schindler (ASF) updated MJAVADOC-370: - Attachment: MJAVADOC-370.patch A new patch that uses the Javascript code as copied

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Uwe Schindler (ASF) updated MJAVADOC-370: - Attachment: MJAVADOC-370.patch I streamlined the patch a bit more and removed the

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Uwe Schindler (ASF) (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327207#comment-327207 ] Uwe Schindler (ASF) edited comment on MJAVADOC-370 at 6/23/13 4:35 PM:

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327210#comment-327210 ] Olivier Lamy commented on MJAVADOC-370: --- applied http://svn.apache.org/r1495902 I will add

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-23 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327211#comment-327211 ] Olivier Lamy commented on MJAVADOC-370: --- disable the patching configurable see

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-22 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327159#comment-327159 ] Olivier Lamy commented on MJAVADOC-370: --- The goal is to have the class JavadocFixTool

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-22 Thread Olivier Lamy (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Olivier Lamy reassigned MJAVADOC-370: - Assignee: Olivier Lamy Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-21 Thread Oleg Kalnichevski (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327120#comment-327120 ] Oleg Kalnichevski commented on MJAVADOC-370: Why not make things simple and just

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-21 Thread Oleg Kalnichevski (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327122#comment-327122 ] Oleg Kalnichevski commented on MJAVADOC-370: The user would also need to add a

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-21 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327125#comment-327125 ] SebbASF commented on MJAVADOC-370: -- That's another possibility, but I still think the Javadoc

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-21 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327127#comment-327127 ] SebbASF commented on MJAVADOC-370: -- @Oleg There is already at least one 3rd party plugin; it is

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread Kristian Rosenvold (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327041#comment-327041 ] Kristian Rosenvold commented on MJAVADOC-370: - How do we know if this license is

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327047#comment-327047 ] SebbASF commented on MJAVADOC-370: -- The license says: We grant you a perpetual, nonexclusive,

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327087#comment-327087 ] SebbASF commented on MJAVADOC-370: -- See also https://issues.apache.org/jira/browse/LEGAL-171.

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327088#comment-327088 ] SebbASF commented on MJAVADOC-370: -- Another possibility might be to rely on a 3rd party

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread Oleg Kalnichevski (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327092#comment-327092 ] Oleg Kalnichevski commented on MJAVADOC-370: If JavadocUpdaterTool is loaded

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread Kristian Rosenvold (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327093#comment-327093 ] Kristian Rosenvold commented on MJAVADOC-370: - @Oleg And where would we get it from

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread Oleg Kalnichevski (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327094#comment-327094 ] Oleg Kalnichevski commented on MJAVADOC-370: @Kristian Classpath would probably be a

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-20 Thread SebbASF (JIRA)
[ https://jira.codehaus.org/browse/MJAVADOC-370?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=327095#comment-327095 ] SebbASF commented on MJAVADOC-370: -- The 3rd party plugin details would need to be provided as a

[jira] (MJAVADOC-370) Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2])

2013-06-19 Thread SebbASF (JIRA)
SebbASF created MJAVADOC-370: Summary: Javadoc vulnerability (CVE-2013-1571 [1], VU#225657 [2]) Key: MJAVADOC-370 URL: https://jira.codehaus.org/browse/MJAVADOC-370 Project: Maven 2.x Javadoc Plugin