PT-2005-1313 · Mozilla+2 · Firefox+4
Eric Johanson
·
Published
2005-02-07
·
Updated
2022-02-28
·
CVE-2005-0233
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox version 1.0
Camino version .8.5
Mozilla versions prior to 1.7.6
Description
The issue allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates. This is done by utilizing homograph characters from other character sets, which can facilitate phishing attacks.
Recommendations
For Firefox version 1.0, update to a version that includes the fix for this issue.
For Camino version .8.5, update to a version that includes the fix for this issue.
For Mozilla versions prior to 1.7.6, update to version 1.7.6 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Camino
Firefox
Mozilla Firefox
Opera
Red Hat