Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5163

Опубликовано: 03 дек. 2019
Источник: debian

Описание

An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowsocks-libevfixed3.3.3+ds-2package
shadowsocks-libevno-dsabusterpackage
shadowsocks-libevno-dsastretchpackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0956

  • https://github.com/shadowsocks/shadowsocks-libev/issues/2536

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.

CVSS3: 7.5
nvd
около 6 лет назад

An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.

CVSS3: 7.5
github
больше 3 лет назад

An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.

suse-cvrf
около 6 лет назад

Security update for shadowsocks-libev