Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5164

Опубликовано: 03 дек. 2019
Источник: debian
EPSS Низкий

Описание

An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowsocks-libevfixed3.3.3+ds-2package
shadowsocks-libevno-dsabusterpackage
shadowsocks-libevno-dsastretchpackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0958

  • https://github.com/shadowsocks/shadowsocks-libev/issues/2537

  • Mitigation: Using a unix socket with ss-manager via --manager-socket.

  • Exposing ss-manager to pubic is always dangerous.

EPSS

Процентиль: 62%
0.00429
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.

CVSS3: 7.8
nvd
около 6 лет назад

An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.

CVSS3: 7.8
github
больше 3 лет назад

An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.

suse-cvrf
около 6 лет назад

Security update for shadowsocks-libev

EPSS

Процентиль: 62%
0.00429
Низкий