Vulnerability Details CVE-2019-5163
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.3%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2019-5163
-
cpe:2.3:a:shadowsocks:shadowsocks-libev:3.3.2
-
cpe:2.3:o:opensuse:backports:sle-15
-
cpe:2.3:o:opensuse:leap:15.1