CVE-2019-5152

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-5152
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5152.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5152
Related
Published
2019-12-18T15:15:11Z
Modified
2025-02-13T05:43:23.698086Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.

References

Affected packages

Debian:11 / shadowsocks-libev

Package

Name
shadowsocks-libev
Purl
pkg:deb/debian/shadowsocks-libev?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.5+ds-4
3.3.5+ds-5
3.3.5+ds-6
3.3.5+ds-7
3.3.5+ds-8
3.3.5+ds-9
3.3.5+ds-10
3.3.5+ds-11
3.3.5+ds-12

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / shadowsocks-libev

Package

Name
shadowsocks-libev
Purl
pkg:deb/debian/shadowsocks-libev?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.5+ds-10
3.3.5+ds-11
3.3.5+ds-12

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / shadowsocks-libev

Package

Name
shadowsocks-libev
Purl
pkg:deb/debian/shadowsocks-libev?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.5+ds-10
3.3.5+ds-11
3.3.5+ds-12

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/shadowsocks/shadowsocks-libev

Affected ranges

Type
GIT
Repo
https://github.com/shadowsocks/shadowsocks-libev
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v1.*

v1.3
v1.3.2
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.1
v1.6.2
v1.6.3
v1.6.4

v2.*

v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.6.0
v2.6.1
v2.6.2
v2.6.3

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.3.0
v3.3.1
v3.3.2