PT-2005-1317 · Kde+1 · Konqueror+1
Eric Johanson
·
Published
2005-02-07
·
Updated
2018-10-19
·
CVE-2005-0237
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Konqueror version 3.2.1
Description
The issue allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates. This is done by utilizing homograph characters from other character sets, which can facilitate phishing attacks.
Recommendations
For Konqueror version 3.2.1, consider disabling the International Domain Name (IDN) support as a temporary workaround until a patch is available. Restrict access to potentially malicious URLs to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Konqueror
Red Hat