Описание
Security update for shadowsocks-libev
This update for shadowsocks-libev fixes the following issues:
Security issue fixed:
- CVE-2017-15924: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions. (boo#1065619)
Список пакетов
openSUSE Leap 42.3
shadowsocks-libev-2.5.6-3.1
shadowsocks-libev-devel-2.5.6-3.1
shadowsocks-libev-doc-2.5.6-3.1
Ссылки
- E-Mail link for openSUSE-SU-2017:3017-1
- SUSE Security Ratings
Описание
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
Затронутые продукты
openSUSE Leap 42.3:shadowsocks-libev-2.5.6-3.1
openSUSE Leap 42.3:shadowsocks-libev-devel-2.5.6-3.1
openSUSE Leap 42.3:shadowsocks-libev-doc-2.5.6-3.1
Ссылки
- CVE-2017-15924
- SUSE Bug 1065619