Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 81115 - www-client/opera: IDN Spoofing Security Issue (CAN-2005-0235)
Summary: www-client/opera: IDN Spoofing Security Issue (CAN-2005-0235)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/14154/
Whiteboard: A4 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-02-07 06:44 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-06-01 07:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-02-07 06:47:31 UTC
Description:
Eric Johanson has reported a security issue in Opera, which can be exploited by a malicious web site to spoof the URL displayed in the address bar, SSL certificate, and status bar.

The problem is caused due to an unintended result of the IDN (International Domain Name) implementation, which allows using international characters in domain names.

This can be exploited by registering domain names with certain international characters that resembles other commonly used characters, thereby causing the user to believe they are on a trusted site.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:
http://secunia.com/multiple_browsers_idn_spoofing_test/

The issue has been confirmed in Opera versions 7.54u1 and 7.54u2. Other versions may also be affected.

Solution:
Don't follow links from untrusted sources.

Manually type the URL in the address bar.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-03-02 06:58:44 UTC
8.0b2 "fixes" this, waiting for a final release.
Comment 2 Elliott Berglund 2005-04-03 16:37:11 UTC
I suppose this could be another workaround for certain sites. Have the wand enabled and a password saved for sites. If you go to a site that appears to be the same but see no yellow hilighting, leave the site.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-19 23:33:52 UTC
8.0 is unleashed.
Comment 4 Heinrich Wendel (RETIRED) gentoo-dev 2005-04-22 10:27:40 UTC
opera-8.00 is now in portage, but i'm against marking it stable, because it's a quite big step from 7.54
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-23 00:38:27 UTC
Heinrich how do you want to proceed?

This bug is rather minor, we could perhaps keep it in ~ for a week and then call arches?
Comment 6 Heinrich Wendel (RETIRED) gentoo-dev 2005-04-23 01:55:47 UTC
Yes, sounds good
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-05-15 08:12:01 UTC
Let's see if we can complete this one.
x86, sparc, amd64: please test and mark stable if you can...
Comment 8 Jan Brinkmann (RETIRED) gentoo-dev 2005-05-15 10:30:15 UTC
stable on amd64
Comment 9 Jason Wever (RETIRED) gentoo-dev 2005-05-15 15:48:27 UTC
Stable on SPARC.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-23 12:00:47 UTC
lanius/tester please mark x86.  
Comment 11 Heinrich Wendel (RETIRED) gentoo-dev 2005-05-31 17:03:23 UTC
finally got time to test it on x86 
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2005-06-01 00:43:59 UTC
Thanks Heinrich

Ready for GLSA vote, my opinion on IDN things is that they should be handled at
registrar level, so I vote NO (and I don't think we did a GLSA for Mozilla on
those things)
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-01 07:23:25 UTC
I agree on NO GLSA -> closing. Feel free to reopen if you disagree.