CVE-2017-15924: Debian Linux
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
Affected products
- Debian Debian Linux: version 9.2 only
- Shadowsocks Shadowsocks-Libev: version 1.3 only; version 1.3.2 only; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; …
Published 2017-10-27. Last modified 2026-06-17.