36451 : Apple Safari / iPhone IDN Unicode Font Support Phishing Weakness
Printer | http://osvdb.org/36451 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
5 464 over 4 years ago over 3 years ago 2 times 5%

This Entry needs help! It is only 5% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Disclosure Date
2007-08-01

Description

<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3742" target="_blank">CVE</a>)</em> : WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing &quot;look-alike characters&quot; (homographs) and possibly perform phishing attacks.

Classification

Location: Mobile Phone / Hand-held Device

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete

CVSSv2 Score

CVSSv2 Base Score = 4.3
Source: nvd.nist.gov | Generated: 2007-08-06 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_0 Integrity_impact_1 Availability_impact_0

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2007/08/01 03:30:03 | Breaking: iPhone Update 1.0.1 Now Available, Fixes Safari Security Breach, Other Bugs

from: Gizmodo, the Gadget Guide

[ hellyeah.jpg]iPhone Firmware Update v1.0.1 is now available through iTunes, and it will "fix bugs." The JesusPhone is getting an apparently minor upgrade, but the consequences are huge to your security. Discover why after the jump. [Last Updated 11:24PM EST - NEW: full listing of changes after the jump.] [ bug-fixes.jpg]

2007/08/01 07:14:26 | Apple iPhone gets first update

from: TechConnect Magazine - Technology news since 1997

It seems like only yesterday that the first hacker got his/her hands on the device and we we're all amazed with the unrealistic sales figures, ... . for reporting this issue. - WebKit (CVE-ID: CVE-2007-3742) Impact: Look-alike characters in a URL could

2007/10/10 14:13:20 | iPhone security concerns how to make sure your phone does not get hacked

from: Techology information and articles

One of the biggest worries about the iPhone ever since it premiered in June 2007 is some rather high profile security concerns about the possibility of hackers being able to get into your iPhone. These security concerns have been based on the ease that people have found to be able to hack into iPhones because of certain security flaws in Mozilla

2007/08/04 06:50:59 | Apple iPhone update 1.0.1 released!

from: iPhone Fan Blog

Apple has just issued an updates v1.0.1 for the iPhone. It fixes the security problem of the Safari web browser ... . Credit to Richard Moore of Westpoint Ltd. for reporting this issue. WebKit CVE-ID: CVE-2007-3742

2007/08/01 01:47:03 | iPhone Update 1.0.1 Now Available, Fixes Safari Security, Other Bugs

from: iPhone Apps

iPhone Update 1.0.1 Now Available, Fixes Safari Security, Other Bugs News No Comments » [ iphone update 1.01] iPhone Firmware Update v1.0.1 is now available, with “bug fixes.” The JesusPhone is getting an apparently minor upgrade, but the consequences are huge to your security. Discover why after the jump. Download it now. • It works

2007/08/01 02:46:36 | Urgent Iphone Update 1.0.1

from: The Best Reviews, Bargains, And Steals On Everything iPhone & Accessories | iPhone Accessory Reviews

Apple has just pushed out a new security update addressing several flaws hackers had identified, but not released into the wild as of yet ... Moore of Westpoint Ltd. for reporting this issue. WebKit CVE-ID: CVE-2007-3742 Available

2007/08/01 02:55:36 | Apple Releases iPhone Software Version 1.0.1

from: 37primeBlog

Apple has released iPhone Software Version 1.0.1 that includes some bug fixes. http://docs.info.apple.com/article.html?artnum=306173 iPhone v1.0 ... CVE-ID: CVE-2007-3742 Available for: iPhone v1.0 Impact: Look-alike characters in a URL could

2007/08/01 02:55:56 | Apple Releases iPhone Software Version 1.0.1

from: 37prime

Apple Releases iPhone Software Version 1.0.1 31 07 2007 Apple has released iPhone Software Version 1.0.1 that includes some bug fixes ... to Richard Moore of Westpoint Ltd. for reporting this issue. WebKit CVE-ID: CVE-2007-3742

2007/08/01 02:56:55 | iPhone Update v1.0.1

from: Ramblings from The Montopolis Group

A few very important updates that need to be applied! Hopefully we’ll get another update here in the next couple months with features instead of security patches! [ :)] I can understand Apple’s need to release patches for the Safari App.. afterall, it is a full fledged browser. Can Windows Mobile IE say that?

2007/08/01 03:17:00 | Breaking: iPhone Update 1.0.1 Now Available, Fixes Safari Security Breach, Other Bugs

from: archive.dailypicture.net

Breaking: iPhone Update 1.0.1 Now Available, Fixes Safari Security Breach, Other Bugs Tuesday, 31 July 2007 9:17 P GMT-06 [ hellyeah.jpg]iPhone Firmware Update v1.0.1 is now available through iTunes, and it will "fix bugs." The JesusPhone is getting an apparently minor upgrade, but the consequences are huge to your security

2007/08/01 05:57:56 | iPhone update 1.0.1

from: Jeff Ledoux

[ iPhone]Apple has updated the iPhone software! It seems like the majority of the update was for the web and safari. I guess they are battling the hacking that’s been going on? It seems to me Safari is running a lot better as well. Although maybe it’s just the new, shiny, luster of an update already. I’m not sure

2007/08/01 08:32:30 | Apple iPhone update 1.0.1 released!

from: Cell Phone News and Reviews

Apple has just issued an updates v1.0.1 for the iPhone. It fixes the security problem of the Safari web browser ... -ID: CVE-2007-3742 Available for: iPhone v1.0 Impact

2007/08/01 09:35:41 | Breaking: iPhone Update 1.0.1 Now Available, Fixes Safari Security Breach, Other Bugs

from: Index of /blog

Breaking: iPhone Update 1.0.1 Now Available, Fixes Safari Security Breach, Other Bugs [ hellyeah.jpg]iPhone Firmware Update v1.0.1 is now available through iTunes, and it will “fix bugs.” The JesusPhone is getting an apparently minor upgrade, but the consequences are huge to your security. Discover why after the jump. [

2007/08/01 17:24:53 | Apple iPhone gets updated - some security patches

from: DarkVision Hardware - enlightens your mind

Apple iPhone gets updated - some security patches Posted on Wednesday, August 01 2007 @ 19:04: ... of Westpoint Ltd. for reporting this issue. WebKit CVE-ID: CVE-2007-3742 Available for: iPhone v1.0

2007/08/02 01:28:52 | Apple Security Update 2007-007

from: Visible Procrastinations

Apple Security Update 2007-007 Published August 2nd, 2007 patch , security , apple 0 Comments Security Update 2007-007 Security Update 2007-07 fixes 45 security vulnerabilities in Mac OS X. All Mac OS X users should install this as a lot of common packages are affected

2007/08/02 06:54:31 | Iphone Release 1.01 is here!

from: Brokeit.COM

Ok so what do we have here....Here it is directly from the Apple page. Looks like bug fixes, no new features, but ehre goes "Phone v1.0 ... this issue. WebKit CVE-ID: CVE-2007-3742 Available for: iPhone v1.0 Impact: Look-alike characters

2007/08/02 15:10:25 | iPhone v1.0.1 Update

from: 499iPhone

This document describes the security content of iPhone v1.0.1 Update, which can be downloaded and installed via iTunes as described below. For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available

2007/08/07 04:41:25 | iPhone software update 1.0.1 released (updated)

from: 1980s Apple Created The World

[ iPhone software update 1.0.1 released] Apple this evening released iPhone Software Update 1.0.1 (1C25, 7.1 MB) ... -ID: CVE-2007-3742 Impact: Look-alike characters in a URL could be used to masquerade a website

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use