First published: Fri Aug 03 2007(Updated: )
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike characters" (homographs) and possibly perform phishing attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone | =1.0 | |
Apple Mobile Safari | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3742 has a moderate severity rating due to the potential for phishing attacks using look-alike URLs.
To fix CVE-2007-3742, update Apple Safari to version 3.0.3 or later and update iPhone to version 1.0.1 or later.
Apple Safari versions before 3.0.3 are affected by CVE-2007-3742.
CVE-2007-3742 facilitates phishing attacks through the use of homograph URLs that mimic legitimate sites.
Only versions of iPhone prior to 1.0.1 are affected by CVE-2007-3742.