Vulnerability Report: GO-2022-0979
- CVE-2022-3346, GHSA-87mm-qxm5-cp3f
- Affects: github.com/peterzen/goresolver
- Published: Sep 29, 2022
- Modified: May 20, 2024
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.
Affected Packages
-
PathGo VersionsSymbols
-
all versions, no known fixedall symbols
Aliases
References
- https://github.com/peterzen/goresolver/issues/5
- https://vuln.go.dev/ID/GO-2022-0979.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.