VDB
GCVE-110-MAGEIA-2014-410
GCVE-110-MAGEIA-2014-410
Advisory Published
Updated golang packages fix security vulnerability:
Go 1.1 through 1.3.2 has an issue that affects programs that use crypto/tls
to implement a TLS server. If the server enables TLS client authentication
using certificates and explicitly sets SessionTicketsDisabled to true in the
tls.Config, then a malicious client can falsely assert ownership of any
client certificate it wishes (CVE-2014-7189).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | config | — | — |
| Mageia | golang | 0 (affected), 1.1.2-3.1.mga4 (unaffected) | — |
References
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.