PT-2005-1317 · Kde+1 · Konqueror+1

Eric Johanson

·

Publicado

2005-02-07

·

Atualizado

2018-10-19

·

CVE-2005-0237

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Konqueror version 3.2.1
Description The issue allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates. This is done by utilizing homograph characters from other character sets, which can facilitate phishing attacks.
Recommendations For Konqueror version 3.2.1, consider disabling the International Domain Name (IDN) support as a temporary workaround until a patch is available. Restrict access to potentially malicious URLs to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0237
RHSA-2005:325
RHSA-2005_325

Produtos afetados

Konqueror
Red Hat