PT-2005-1315 · Opera · Opera

Eric Johanson

·

Published

2005-02-07

·

Updated

2022-02-28

·

CVE-2005-0235

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Opera version 7.54
Description The issue allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates. This is done in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
Recommendations For Opera version 7.54, consider disabling the International Domain Name (IDN) support as a temporary workaround until a patch is available. Restrict access to punycode encoded domain names to minimize the risk of exploitation. Avoid using homograph characters from other character sets in URLs and SSL certificates until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0235

Affected Products

Opera