CVE-2019-5152
published 2019-12-18CVE-2019-5152: An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream…
PriorityP343high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.38%
69.3th percentile
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadowsocks-libev | — | — |
| shadowsocks | shadowsocks-libev | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-5152: shadowsocks-libev - An exploitable information disclosure vulnerability exists in the network packet...
vendor_debian·2019·CVSS 7.4
CVE-2019-5152 [HIGH] CVE-2019-5152: shadowsocks-libev - An exploitable information disclosure vulnerability exists in the network packet...
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-pmr7-f238-jxqj: An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3
ghsa_unreviewed·2022-05-24
CVE-2019-5152 [MEDIUM] CWE-306 GHSA-pmr7-f238-jxqj: An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.
OSV
CVE-2019-5152: An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3
osv·2019-12-18·CVSS 7.4
CVE-2019-5152 [HIGH] CVE-2019-5152: An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published