CVE-2005-0237: Medium severity KDE Konqueror vulnerability
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0237?
CVE-2005-0237 is considered a high severity vulnerability due to the potential for phishing attacks through domain name spoofing.
How do I fix CVE-2005-0237?
To fix CVE-2005-0237, upgrade to a patched version of Konqueror that addresses the issue with IDN support.
What software is affected by CVE-2005-0237?
CVE-2005-0237 affects Konqueror version 3.2.1 on KDE 3.2.1.
What type of attack does CVE-2005-0237 enable?
CVE-2005-0237 enables attackers to conduct phishing attacks by spoofing domain names using homograph characters.
Can CVE-2005-0237 impact SSL certificates?
Yes, CVE-2005-0237 can impact SSL certificates by allowing spoofed domain names in SSL contexts.