UBUNTU-CVE-2017-15924
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-15924
Summary:
Details: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
References: https://ubuntu.com/security/CVE-2017-15924, https://www.x41-dsec.de/lab/advisories/x41-2017-010-shadowsocks-libev/, https://github.com/shadowsocks/shadowsocks-libev/issues/1734, https://github.com/shadowsocks/shadowsocks-libev/commit/c67d275, http://openwall.com/lists/oss-security/2017/10/13/2, https://www.cve.org/CVERecord?id=CVE-2017-15924
Affected packages
Package
Name: shadowsocks-libev
Purl: pkg:deb/ubuntu/[email protected]+ds-1ubuntu2?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
