CVE-2017-15924OS Command Injection in Shadowsocks-libev

Severity
7.8HIGHNVD
EPSS
0.5%
top 36.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianshadowsocks/shadowsocks-libev< 3.1.0+ds-2+3
NVDshadowsocks/shadowsocks-libev70 versions+69

Also affects: Debian Linux 9.2

🔴Vulnerability Details

3
GHSA
GHSA-mvjw-f63r-3gxc: In manager2022-05-13
CVEList
CVE-2017-15924: In manager2017-10-27
OSV
CVE-2017-15924: In manager2017-10-27

📋Vendor Advisories

1
Debian
CVE-2017-15924: shadowsocks-libev - In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows c...2017
CVE-2017-15924 — OS Command Injection | cvebase