CNCVE编号:CNCVE-20001117 CVE编号:CAN-2000-1117 安全级别:低 漏洞中文描述: Lotus Notes Client R5中的Java虚拟机 (JVM)的Extended Control List (ECL) 功能允许恶意网站操作员通过在执行getSystemResource方法中测量延迟来确定客户端文件的存在。 漏洞英文描述: The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method. 漏洞参考: BUGTRAQ:20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.html | BID:1994 | URL:http://www.securityfocus.com/bid/1994 系统类型:其他 漏洞类型:权限有效性检查错误