Описание
go-resolver's DNSSEC validation not performed correctly
go-resolver's DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.
Пакеты
Наименование
github.com/peterzen/goresolver
go
Затронутые версииВерсия исправления
<= 1.0.2
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
около 3 лет назад
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.