An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-14769 An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-08-04T19:47:56.612Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5164

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-03T22:15:15.433

Modified: 2024-11-21T04:44:28.367

Link: CVE-2019-5164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.