#VU23394 Information disclosure in Shadowsocks-libev - CVE-2019-5152
Published: December 4, 2019 / Updated: January 30, 2020
Shadowsocks-libev
Shadowsocks
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the network packet handling functionality when utilizing a Stream Cipher. A remote attacker can send a specially crafted set of network packets, cause an outbound connection from the server and gain unauthorized access to sensitive information on the system.