openSUSE has issued an advisory on December 11: https://lists.opensuse.org/opensuse-updates/2019-12/msg00070.html Mageia 7 is also affected.
The issues are fixed upstream in 3.3.3.
CC: (none) => eatdirtWhiteboard: (none) => MGA7TOO
Already done for Cauldron!
CC: (none) => geiger.david68210
And now done for mga7!
Advisory: ======================== Updated shadowsocks-libev packages fix security vulnerabilities: Exploitable denial-of-service vulnerability exists in the UDPRelay functionality (CVE-2019-5163). Code execution vulnerability in the ss-manager binary (CVE-2019-5164). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5163 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5164 https://lists.opensuse.org/opensuse-updates/2019-12/msg00070.html ======================== Updated packages in core/updates_testing: ======================== shadowsocks-libev-3.3.3-1.mga7 libshadowsocks2-3.3.3-1.mga7 libshadowsocks-devel-3.3.3-1.mga7 from shadowsocks-libev-3.3.3-1.mga7.src.rpm
CC: (none) => olavSource RPM: shadowsocks-libev-3.3.0-1.mga8.src.rpm => shadowsocks-libev-3.2.3-2.mga7.src.rpmVersion: Cauldron => 7Assignee: olav => qa-bugsWhiteboard: MGA7TOO => (none)
MGA7-64 Plasma on Lenovo B50 No installation issues. Bug 22037 decided OK on clean install.Did a little research and found: https://www.tipsforchina.com/how-to-setup-a-fast-shadowsocks-server-on-vultr-vps-the-easy-way.html Does look like something I want to venture into.
Whiteboard: (none) => MGA7-64-OKCC: (none) => herman.viaene
Validating. Advisory in Comment 4.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisoryCC: (none) => tmb
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2020-0006.html
Status: NEW => RESOLVEDResolution: (none) => FIXED