CVE-2019-5164: Opensuse Backports Sle
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
Affected products
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only
- Shadowsocks Shadowsocks-Libev: version 3.3.2 only
Published 2019-12-03. Last modified 2026-06-17.