PT-2005-1316 · Omni · Omniweb
Eric Johanson
·
Published
2005-02-07
·
Updated
2017-07-11
·
CVE-2005-0236
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Omniweb version 5
Description
The issue concerns the International Domain Name (IDN) support, which allows remote attackers to spoof domain names. This is achieved by using punycode encoded domain names that are decoded in URLs and SSL certificates, leveraging homograph characters from other character sets. This facilitates phishing attacks.
Recommendations
For Omniweb version 5, consider disabling the IDN support as a temporary workaround until a patch is available. Restrict access to URLs and SSL certificates that use punycode encoded domain names to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Omniweb