HIGH
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2
Published Dec 3, 2019
7.8
HIGHCVSS 3.1
EPSS 0.76%
Description
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
Affected products
- Vendor n/a Product Shadowsocks Defaultn/a
- Version Shadowsocks-libev 3.3.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Shadowsocks | n/a |
|
Configuration 1
- 3.3.2
Configuration 2
OR
- 15.0
- 15.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00023.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00061.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0958 x_refsource_MISCExploitMitigationThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00023.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00061.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0958 | x_refsource_MISCExploitMitigationThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Dec 3, 2019
Updated Aug 4, 2024
Reserved Jan 4, 2019
Link CVE-2019-5164
CISA Vulnrichment
Updated n/a