CVE

Id
1710  
CVE No.
CVE-2000-0132  
Status
Candidate  
Description
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.  
Phase
Proposed (20000208)  
Votes
ACCEPT(2) Cole, Wall | NOOP(1) Baker | REJECT(3) Christey, Frech, LeBlanc  
Comments
Frech> How is this different from MITRE:CVE-2000-0162, other than the | fact that it has an MS advisory that"s vague on the reason but | has the same outcome, and this one mentions the | getSystemResourceAsStream function? | Christey> This is a duplicate of CVE-2000-0162, as confirmed via David | LeBlanc. The descriptions of CVE-2000-0132 and CVE-2000-0162 were | significantly different, as was the descriptive text of | MS:MS00-011 and the original Bugtraq posting. So this | duplicate wasn"t picked up before. CVE-2000-0162 needs to be | modified to include XF:virtual-machine-file-read as a | reference. | LeBlanc> Duplicate | Christey> Ensure that CVE-2000-0162 uses msvm-java-file-read(4024) now, | instead of virtual-machine-file-read(4577) | Frech> If duplicate with CVE-2000-0098, shouldn"t the references be | moved over to the valid CVE number? Please advise. | Christey> When CVE-2000-0132 is rejected, the references will be added | to CVE-2000-0098.