GHSA-87mm-qxm5-cp3f

Source
https://github.com/advisories/GHSA-87mm-qxm5-cp3f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-87mm-qxm5-cp3f/GHSA-87mm-qxm5-cp3f.json
Aliases
Published
2022-12-28T03:30:28Z
Modified
2023-11-08T04:09:39.785061Z
Details

go-resolver's DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.

References

Affected packages

Go / github.com/peterzen/goresolver

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
1.0.2