First published: Wed Dec 18 2019(Updated: )
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shadowsocks Shadowsocks-libev | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5152 is an information disclosure vulnerability that exists in the network packet handling functionality of Shadowsocks-libev 3.3.2.
CVE-2019-5152 can allow an attacker to cause an outbound connection from the server, resulting in information disclosure.
CVE-2019-5152 has a severity rating of 7.4 (High).
CVE-2019-5152 affects Shadowsocks-libev version 3.3.2.
To fix CVE-2019-5152, it is recommended to update Shadowsocks-libev to a version that has addressed the vulnerability.