MGASA-2017-0436

Source
https://advisories.mageia.org/MGASA-2017-0436.html
Import Source
https://advisories.mageia.org/MGASA-2017-0436.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0436
Related
Published
2017-12-01T23:13:21Z
Modified
2017-12-01T22:46:59Z
Summary
Updated shadowsocks-libev packages fix security vulnerability
Details

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the addserver, buildconfig, and constructcommandline functions

References
Credits

Affected packages