Vulnerabilities > CVE-2005-0234 - Unspecified vulnerability in Apple Safari 1.2.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html
- http://www.shmoo.com/idn
- http://www.shmoo.com/idn/homograph.txt
- http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html
- http://www.securityfocus.com/bid/12461
- http://marc.info/?l=bugtraq&m=110782704923280&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19236