Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:3017-1

Опубликовано: 15 нояб. 2017
Источник: suse-cvrf

Описание

Security update for shadowsocks-libev

This update for shadowsocks-libev fixes the following issues:

Security issue fixed:

  • CVE-2017-15924: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions. (boo#1065619)

Список пакетов

openSUSE Leap 42.3
shadowsocks-libev-2.5.6-3.1
shadowsocks-libev-devel-2.5.6-3.1
shadowsocks-libev-doc-2.5.6-3.1

Описание

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.


Затронутые продукты
openSUSE Leap 42.3:shadowsocks-libev-2.5.6-3.1
openSUSE Leap 42.3:shadowsocks-libev-devel-2.5.6-3.1
openSUSE Leap 42.3:shadowsocks-libev-doc-2.5.6-3.1

Ссылки