CVE-2014-7189: Medium severity golang vulnerability
Published Oct 7, 2014
·Updated
crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.
Affected Software
8 affected components
Golang Go=1.1
Golang Go=1.1.1
Golang Go=1.1.2
Golang Go=1.2
Golang Go=1.2.1
Golang Go=1.2.2
Golang Go=1.3
Golang Go=1.3.1
Event History
Oct 7, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7189?
CVE-2014-7189 is considered a high severity vulnerability due to the risk of man-in-the-middle attacks.
2
How do I fix CVE-2014-7189?
To mitigate CVE-2014-7189, upgrade to Go versions 1.3.2 or later where the vulnerability is addressed.
3
What systems are affected by CVE-2014-7189?
CVE-2014-7189 affects Go versions 1.1 through 1.3.1 when SessionTicketsDisabled is enabled.
4
What type of vulnerability is CVE-2014-7189?
CVE-2014-7189 is a security vulnerability associated with TLS that allows for client spoofing.
5
Who is affected by CVE-2014-7189?
Users and developers utilizing vulnerable versions of the Go programming language are at risk for CVE-2014-7189.