debian · CVE-2019-5152

Quick triage

Priority: unimportant Published: Updated: Tue, 30 Jun 2026 01:59:28 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-5152 unimportant priority: Debian including 1 source packages (shadowsocks-libev), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5.

Description:

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.

cvelogic Threat Intelligence