PT-2005-1314 · Apple · Safari
Eric Johanson
·
Publicado
2005-02-07
·
Atualizado
2017-07-11
·
CVE-2005-0234
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Safari version 1.2.5
Description
The issue allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates. This is done in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
Recommendations
For Safari version 1.2.5, consider disabling the International Domain Name (IDN) support as a temporary workaround until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Safari