Bug 898901 (CVE-2014-7189) - VUL-0: go: CVE-2014-7189: TLS client authentication issue fixed in version 1.3.2
Summary: VUL-0: go: CVE-2014-7189: TLS client authentication issue fixed in version 1.3.2
Status: RESOLVED FIXED
Alias: CVE-2014-7189
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Flavio Castelli
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/108615/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-09-29 06:19 UTC by Marcus Meissner
Modified: 2019-10-17 14:26 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2014-09-29 06:19:53 UTC
via oss-sec

From the Go 1.3.2 release announcement:

"The crpyto/tls fix addresses a security bug that affects programs that use
crypto/tls to implement a TLS server from Go 1.1 onwards. If the server enables
TLS client authentication using certificates (this is rare) and explicitly sets
SessionTicketsDisabled to true in the tls.Config, then a malicious client can
falsely assert ownership of any client certificate it wishes."

https://groups.google.com/forum/#!msg/golang-nuts/eeOHNw_shwU/OHALUmroA5kJ
Comment 1 SMASH SMASH 2014-09-29 06:25:19 UTC
Affected packages:

SLE-12: go
Comment 2 Swamp Workflow Management 2014-10-01 12:07:27 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2014-10-31 10:00:30 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/259106 13.2 / go
Comment 6 Swamp Workflow Management 2014-11-13 09:04:50 UTC
openSUSE-SU-2014:1411-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 898901
CVE References: CVE-2014-5277,CVE-2014-7189
Sources used:
openSUSE 13.2 (src):    docker-1.3.1-5.2, go-1.3.3-5.1
Comment 7 Flavio Castelli 2014-11-27 13:46:31 UTC
Updated package submitted.
Comment 8 Marcus Meissner 2014-11-27 20:42:52 UTC
I accepted and merged it for SLE12, thanks.
Comment 9 Flavio Castelli 2014-12-10 15:49:56 UTC
Why is this package still not available to our customers?
Comment 10 Johannes Segitz 2014-12-10 16:22:05 UTC
(In reply to Flavio Castelli from comment #9)
SUSE:Maintenance:119 is still in QA, I will ask them to speed this up
Comment 11 Flavio Castelli 2014-12-11 08:59:19 UTC
This package is in tech preview, so there's no need to perform QA on that.
Comment 12 Swamp Workflow Management 2014-12-15 13:04:51 UTC
SUSE-SU-2014:1648-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 898901,902289,902413,907012,907014
CVE References: CVE-2014-5277,CVE-2014-5282,CVE-2014-6407,CVE-2014-6408,CVE-2014-7189
Sources used:
SUSE Linux Enterprise Server 12 (src):    docker-1.3.2-9.1, sle2docker-0.2.3-5.1
Comment 13 Marcus Meissner 2014-12-15 13:18:44 UTC
released
Comment 14 Swamp Workflow Management 2015-08-31 14:10:25 UTC
openSUSE-RU-2015:1458-1: An update that has 5 recommended fixes can now be installed.

Category: recommended (low)
Bug References: 818502,898901,931301,935570,939067
CVE References: 
Sources used:
openSUSE 13.2 (src):    docker-1.7.1-34.3, go-1.4.2-12.1, golang-github-cpuguy83-go-md2man-1.0.2+git20150617.e69ac41-2.2, golang-github-russross-blackfriday-1.2.0+git20150720.8cec3a8-2.3, golang-github-shurcool-sanitized_anchor_name-0.0.0+git20150514.11a20b7-2.2, golang-org-x-net-1.4.2+git20150629.d9558e5-2.3, golang-org-x-text-1.4.2+git20150710.7c0e16d-2.2, golang-packaging-6-2.1
Comment 15 Swamp Workflow Management 2018-05-17 17:01:24 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/610123 Factory / go1.10
Comment 23 Swamp Workflow Management 2018-12-15 08:41:59 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/658307 Factory / go1.10
https://build.opensuse.org/request/show/658308 Factory / go1.11
Comment 25 Swamp Workflow Management 2018-12-17 15:43:33 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/658934 15.0+42.3 / go1.11
Comment 26 Swamp Workflow Management 2019-02-27 11:02:28 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/679777 Factory / go1.11
Comment 27 Swamp Workflow Management 2019-03-25 11:12:57 UTC
This is an autogenerated message for OBS integration:
This bug (898901) was mentioned in
https://build.opensuse.org/request/show/688187 Factory / go1.12