Candidate: CVE-2019-5163 PublicDate: 2019-12-03 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5163 https://talosintelligence.com/vulnerability_reports/TALOS-2019-0956 https://github.com/shadowsocks/shadowsocks-libev/issues/2536 Description: An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_shadowsocks-libev: upstream_shadowsocks-libev: released (3.3.3+ds-2) precise/esm_shadowsocks-libev: DNE trusty_shadowsocks-libev: ignored (out of standard support) trusty/esm_shadowsocks-libev: DNE xenial_shadowsocks-libev: DNE bionic_shadowsocks-libev: needs-triage disco_shadowsocks-libev: ignored (reached end-of-life) eoan_shadowsocks-libev: ignored (reached end-of-life) focal_shadowsocks-libev: not-affected (3.3.3+ds-3) groovy_shadowsocks-libev: not-affected (3.3.3+ds-3) hirsute_shadowsocks-libev: not-affected (3.3.3+ds-3) impish_shadowsocks-libev: not-affected (3.3.3+ds-3) jammy_shadowsocks-libev: not-affected (3.3.3+ds-3) devel_shadowsocks-libev: not-affected (3.3.3+ds-3)