MGASA-2014-0410
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 09 Oct 2014, 14:39
Last modified:16 Apr 2026, 06:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Oct 2014, 14:39
Published
Vulnerability first disclosed
16 Apr 2026, 06:23
Last Modified
Vulnerability information updated
Description
Updated golang packages fix CVE-2014-7189 Updated golang packages fix security vulnerability: Go 1.1 through 1.3.2 has an issue that affects programs that use crypto/tls to implement a TLS server. If the server enables TLS client authentication using certificates and explicitly sets SessionTicketsDisabled to true in the tls.Config, then a malicious client can falsely assert ownership of any client certificate it wishes (CVE-2014-7189).
Affected Systems
- mageia•golang
< 1.1.2-3.1.mga4