Candidate: CVE-2019-5164 PublicDate: 2019-12-03 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5164 https://talosintelligence.com/vulnerability_reports/TALOS-2019-0958 https://github.com/shadowsocks/shadowsocks-libev/issues/2537 Description: An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_shadowsocks-libev: upstream_shadowsocks-libev: released (3.3.3+ds-2) precise/esm_shadowsocks-libev: DNE trusty_shadowsocks-libev: ignored (out of standard support) trusty/esm_shadowsocks-libev: DNE xenial_shadowsocks-libev: DNE bionic_shadowsocks-libev: needs-triage disco_shadowsocks-libev: ignored (reached end-of-life) eoan_shadowsocks-libev: ignored (reached end-of-life) focal_shadowsocks-libev: not-affected (3.3.3+ds-3) groovy_shadowsocks-libev: not-affected (3.3.3+ds-3) hirsute_shadowsocks-libev: not-affected (3.3.3+ds-3) impish_shadowsocks-libev: not-affected (3.3.3+ds-3) jammy_shadowsocks-libev: not-affected (3.3.3+ds-3) devel_shadowsocks-libev: not-affected (3.3.3+ds-3)