Advisory: Opera may show some incorrect characters in the address bar

August 29, 2009

Summary

Some Unicode characters are treated incorrectly, which might cause international domain names that use them to be shown in the wrong format. Showing these addresses in Unicode instead of punycode could allow for limited address spoofing.

Severity

Less severe

Opera's response

Opera Software has released Opera 10.00, where this issue has been fixed.

Credits

Thanks to Chris Weber of Casaba Security for reporting this issue to Opera Software.