ZeroHour

CVE-2019-5152

PoC
CVSS 3.1
7.4 high
EPSS
1%p71
Published
()
Modified
Description

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.

Vendors
shadowsocks
Products
shadowsocks-libev
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.