CVE-2022-3347
28.12.2022, 03:15
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.Enginsight
Vendor | Product | Version |
---|---|---|
go-resolver_project | go-resolver | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration