Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-3742
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3742

Description:
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike characters" (homographs) and possibly perform phishing attacks.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35716

ST
  1018488

SAID
  Secunia Advisory: SA26287

MISC
  http://isc.sans.org/diary.html?storyid=3214

CONFIRM
  http://docs.info.apple.com/article.html?artnum=306174
  http://docs.info.apple.com/article.html?artnum=306173

BID
  24636


Return to the previous page.