CVE-2019-5152

HIGH

Shadowsocks-libev <3.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0942

Scores

CVSS v3 7.4
EPSS 0.0138
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (1)
shadowsocks/shadowsocks-libev 3.3.2
Published Dec 18, 2019
Tracked Since Feb 18, 2026