CVE-2019-5152

Source
https://cve.org/CVERecord?id=CVE-2019-5152
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5152.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5152
Downstream
Published
2019-12-18T15:15:11.333Z
Modified
2026-07-08T12:43:43.683863Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.

References

Affected packages

Git / github.com/shadowsocks/shadowsocks-libev

Affected ranges

Type
GIT
Repo
https://github.com/shadowsocks/shadowsocks-libev
Events
Database specific
{
    "cpe": "cpe:2.3:a:shadowsocks:shadowsocks-libev:3.3.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.3.2"
        },
        {
            "last_affected": "3.3.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.3.2
v3.*
v3.3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5152.json"