Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
Link | Tags |
---|---|
http://secunia.com/advisories/43068 | third party advisory vendor advisory |
http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.html | patch vendor advisory |
http://www.vupen.com/english/advisories/2011/0212 | vdb entry vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html | vendor advisory |
http://www.securitytracker.com/id?1022719 | vdb entry |
http://www.securityfocus.com/bid/36026 | vdb entry patch |
http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html | vendor advisory |
http://secunia.com/advisories/36677 | third party advisory vendor advisory |
http://support.apple.com/kb/HT3860 | |
http://support.apple.com/kb/HT3733 | patch vendor advisory |