CVE-2019-5163: High severity shadowsocks vulnerability
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a localaddress, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-5163.
What is the severity of CVE-2019-5163?
The severity of CVE-2019-5163 is high.
What is the affected software for CVE-2019-5163?
The affected software for CVE-2019-5163 is Shadowsocks-libev 3.3.2, Opensuse Backports sle-15-sp1, and openSUSE Leap 15.1.
How does the vulnerability work?
The vulnerability allows an attacker to send arbitrary UDP packets to trigger a denial-of-service condition.
Are there any references for CVE-2019-5163?
Yes, you can find more information about CVE-2019-5163 at the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00023.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00061.html), [link3](https://talosintelligence.com/vulnerability_reports/TALOS-2019-0956).