dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
References
Link | Resource |
---|---|
https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner | Third Party Advisory |
https://sourceforge.net/projects/dproxy/ | Third Party Advisory |
https://www.openwall.com/lists/oss-security/2022/08/14/3 | Exploit Mailing List Third Party Advisory |
Configurations
Information
Published : 2022-08-15 06:15
Updated : 2022-08-18 09:46
NVD link : CVE-2022-33991
Mitre link : CVE-2022-33991
JSON object : View
CWE
CWE-290
Authentication Bypass by Spoofing
Products Affected
dproxy-nexgen_project
- dproxy-nexgen