7.8

CVE-2017-15924

Exploit

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ShadowsocksShadowsocks-libev Version1.3.2
ShadowsocksShadowsocks-libev Version1.4.0
ShadowsocksShadowsocks-libev Version1.4.1
ShadowsocksShadowsocks-libev Version1.4.2
ShadowsocksShadowsocks-libev Version1.4.3
ShadowsocksShadowsocks-libev Version1.4.4
ShadowsocksShadowsocks-libev Version1.4.5
ShadowsocksShadowsocks-libev Version1.4.6
ShadowsocksShadowsocks-libev Version1.4.7
ShadowsocksShadowsocks-libev Version1.4.8
ShadowsocksShadowsocks-libev Version1.5.0
ShadowsocksShadowsocks-libev Version1.5.1
ShadowsocksShadowsocks-libev Version1.5.2
ShadowsocksShadowsocks-libev Version1.5.3
ShadowsocksShadowsocks-libev Version1.6.1
ShadowsocksShadowsocks-libev Version1.6.2
ShadowsocksShadowsocks-libev Version1.6.3
ShadowsocksShadowsocks-libev Version1.6.4
ShadowsocksShadowsocks-libev Version2.0.1
ShadowsocksShadowsocks-libev Version2.0.2
ShadowsocksShadowsocks-libev Version2.0.3
ShadowsocksShadowsocks-libev Version2.0.4
ShadowsocksShadowsocks-libev Version2.0.5
ShadowsocksShadowsocks-libev Version2.0.6
ShadowsocksShadowsocks-libev Version2.0.7
ShadowsocksShadowsocks-libev Version2.0.8
ShadowsocksShadowsocks-libev Version2.1.0
ShadowsocksShadowsocks-libev Version2.1.1
ShadowsocksShadowsocks-libev Version2.1.2
ShadowsocksShadowsocks-libev Version2.1.3
ShadowsocksShadowsocks-libev Version2.1.4
ShadowsocksShadowsocks-libev Version2.2.0
ShadowsocksShadowsocks-libev Version2.2.1
ShadowsocksShadowsocks-libev Version2.2.2
ShadowsocksShadowsocks-libev Version2.2.3
ShadowsocksShadowsocks-libev Version2.3.0
ShadowsocksShadowsocks-libev Version2.3.1
ShadowsocksShadowsocks-libev Version2.3.2
ShadowsocksShadowsocks-libev Version2.3.3
ShadowsocksShadowsocks-libev Version2.4.0
ShadowsocksShadowsocks-libev Version2.4.1
ShadowsocksShadowsocks-libev Version2.4.2
ShadowsocksShadowsocks-libev Version2.4.3
ShadowsocksShadowsocks-libev Version2.4.4
ShadowsocksShadowsocks-libev Version2.4.5
ShadowsocksShadowsocks-libev Version2.4.6
ShadowsocksShadowsocks-libev Version2.4.7
ShadowsocksShadowsocks-libev Version2.4.8
ShadowsocksShadowsocks-libev Version2.5.0
ShadowsocksShadowsocks-libev Version2.5.1
ShadowsocksShadowsocks-libev Version2.5.2
ShadowsocksShadowsocks-libev Version2.5.3
ShadowsocksShadowsocks-libev Version2.5.4
ShadowsocksShadowsocks-libev Version2.5.5
ShadowsocksShadowsocks-libev Version2.5.6
ShadowsocksShadowsocks-libev Version2.6.0
ShadowsocksShadowsocks-libev Version2.6.1
ShadowsocksShadowsocks-libev Version2.6.2
ShadowsocksShadowsocks-libev Version2.6.3
ShadowsocksShadowsocks-libev Version3.0.0
ShadowsocksShadowsocks-libev Version3.0.1
ShadowsocksShadowsocks-libev Version3.0.2
ShadowsocksShadowsocks-libev Version3.0.3
ShadowsocksShadowsocks-libev Version3.0.4
ShadowsocksShadowsocks-libev Version3.0.5
ShadowsocksShadowsocks-libev Version3.0.6
ShadowsocksShadowsocks-libev Version3.0.7
ShadowsocksShadowsocks-libev Version3.0.8
ShadowsocksShadowsocks-libev Version3.1.0
DebianDebian Linux Version9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.607
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.