CVE Vulnerabilities

CVE-2014-7189

Published: Oct 07, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
GoGolang1.1 (including)1.1 (including)
GoGolang1.1.1 (including)1.1.1 (including)
GoGolang1.1.2 (including)1.1.2 (including)
GoGolang1.2 (including)1.2 (including)
GoGolang1.2.1 (including)1.2.1 (including)
GoGolang1.2.2 (including)1.2.2 (including)
GoGolang1.3 (including)1.3 (including)
GoGolang1.3.1 (including)1.3.1 (including)
GolangUbuntuprecise*
GolangUbuntutrusty*
GolangUbuntuupstream*
GolangUbuntuutopic*

References