CVE Vulnerabilities

CVE-2014-7189

Published: Oct 07, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Go Golang 1.1 (including) 1.1 (including)
Go Golang 1.1.1 (including) 1.1.1 (including)
Go Golang 1.1.2 (including) 1.1.2 (including)
Go Golang 1.2 (including) 1.2 (including)
Go Golang 1.2.1 (including) 1.2.1 (including)
Go Golang 1.2.2 (including) 1.2.2 (including)
Go Golang 1.3 (including) 1.3 (including)
Go Golang 1.3.1 (including) 1.3.1 (including)
Golang Ubuntu precise *
Golang Ubuntu trusty *
Golang Ubuntu upstream *
Golang Ubuntu utopic *

References