CVE-2022-3346
28.12.2022, 03:15
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.Enginsight
Vendor | Product | Version |
---|---|---|
go-resolver_project | go-resolver | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration