Oval Definition:oval:org.opensuse.security:def:110108
Revision Date:2019-12-11Version:1
Title:Security update for shadowsocks-libev (Moderate)
Description:

This update for shadowsocks-libev fixes the following issues:

- Update version to 3.3.3 * Refine the handling of suspicious connections. * Fix exploitable denial-of-service vulnerability exists in the UDPRelay functionality (boo#1158251, CVE-2019-5163) * Fix code execution vulnerability in the ss-manager binary (boo#1158365, CVE-2019-5164) * Refine the handling of fragment request. * Fix a high CPU bug introduced in 3.3.0. (#2449) * Enlarge the socket buffer size to 16KB. * Fix the empty list bug in ss-manager. * Fix the IPv6 address parser. * Fix a bug of port parser. * Fix a crash with MinGW. * Refine SIP003 plugin interface. * Remove connection timeout from all clients. * Fix the alignment bug again. * Fix a bug on 32-bit arch. * Add TCP fast open support to ss-tunnel by @PantherJohn.


Family:unixClass:patch
Status:Reference(s):1158251
1158365
CVE-2019-5163
CVE-2019-5164
openSUSE-SU-2019:2667-1
Platform(s):openSUSE Leap 15.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libshadowsocks-libev2-3.3.3-lp151.2.3.1 is installed
  • OR shadowsocks-libev-3.3.3-lp151.2.3.1 is installed
  • OR shadowsocks-libev-devel-3.3.3-lp151.2.3.1 is installed
  • OR shadowsocks-libev-doc-3.3.3-lp151.2.3.1 is installed
  • BACK