hickory-resolver 在 0.26.2 版本之前,未能通过 和 接口正确传播虚假的 DNSSEC 验证状态,导致无效的 DNS 记录可能被作为成功结果返回。控制应答区域的攻击者,或位于网络路径上的攻击者,可以利用该漏洞使伪造的 DNS 记录被接受为已验证状态,从而绕过 DNSSEC 身份验证检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hickory-dns | hickory-resolver | < 0.26.2 |
affected |
0.26.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hickory-dns | hickory-resolver | 0 ~ 0.26.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet