CVE-2022-3347: Incorrect validation of root DNSSEC public keys in github.com/peterzen/goresolver
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3347?
CVE-2022-3347 has a medium severity rating due to its potential to allow attackers to manipulate DNSSEC validation.
How do I fix CVE-2022-3347?
To fix CVE-2022-3347, update the goresolver package to version 1.0.3 or later where the vulnerability has been addressed.
What impact does CVE-2022-3347 have on affected systems?
CVE-2022-3347 can allow attackers to present false validation responses, compromising the integrity of DNS queries.
Which software is affected by CVE-2022-3347?
CVE-2022-3347 affects versions of the goresolver package up to and including version 1.0.2.
Is CVE-2022-3347 a known issue?
Yes, CVE-2022-3347 is a recognized vulnerability documented in security advisories and issue trackers.