CVE-2022-3346: Incorrect DNSSEC validation due to unchecked owner names in github.com/peterzen/goresolver
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3346?
CVE-2022-3346 has been categorized as a critical severity vulnerability.
How do I fix CVE-2022-3346?
To fix CVE-2022-3346, upgrade the goresolver package to a version beyond 1.0.2 that addresses this validation issue.
What impact does CVE-2022-3346 pose to my system?
CVE-2022-3346 allows attackers to exploit improper DNSSEC validation, potentially resulting in successful validation of malicious records.
Which versions of goresolver are affected by CVE-2022-3346?
CVE-2022-3346 affects the goresolver package versions up to and including 1.0.2.
Can CVE-2022-3346 allow DNS spoofing attacks?
Yes, CVE-2022-3346 can enable DNS spoofing attacks by misleading the resolver into accepting fraudulent DNS responses.