Vulnerability Report: GO-2022-1026
- CVE-2022-3347, GHSA-jr65-gpj5-cw74
- Affects: github.com/peterzen/goresolver
- Published: Sep 29, 2022
- Modified: May 20, 2024
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.
Affected Packages
-
PathGo VersionsSymbols
-
all versions, no known fixedall symbols
Aliases
References
- https://github.com/peterzen/goresolver/issues/5#issuecomment-1150214257
- https://vuln.go.dev/ID/GO-2022-1026.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.