Overview
Multiple web browsers are vulnerable to spoofing attacks through the use of Internationalized Domain Names. Other applications such as email programs may also be vulnerable.
Description
The Domain Name System The Domain Name System (DNS) provides name, address, and other information about Internet Protocol (IP) networks and devices. DNS was designed to support domain names that use a subset of the American Standard Code for Information Interchange (ASCII) character set. |
Impact
By making a malicious web site appear to be a site that the user trusts, an attacker could convince the user to provide sensitive information. |
Solution
Upgrade or Patch |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cs.technion.ac.il/~gabr/papers/homograph.html
- http://www.apps.ietf.org/rfc/rfc3490.html
- http://www.apps.ietf.org/rfc/rfc3492.html
- http://www.icann.org/committees/idn/idn-codepoint-paper.htm
- http://www.icann.org/topics/idn.html
- http://www.nic.ac/idnfaq.html
- http://unicode.org/reports/tr36/#international_domain_names
- http://www.shmoo.com/idn/
- http://secunia.com/multiple_browsers_idn_spoofing_test/
- http://www.osvdb.org/displayvuln.php?osvdb_id=13578
- https://bugzilla.mozilla.org/show_bug.cgi?id=279099
- http://www.kde.org/info/security/advisory-20050316-2.txt
- http://docs.info.apple.com/article.html?artnum=301061
Acknowledgements
This vulnerability was publicly disclosed by Evgeniy Gabrilovich and Alex Gontmakher.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2005-0234 |
Severity Metric: | 2.36 |
Date Public: | 2002-02-02 |
Date First Published: | 2005-03-22 |
Date Last Updated: | 2005-08-01 14:29 UTC |
Document Revision: | 40 |