NA

CVE-2023-23589

Published: 14/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The SafeSocks option in Tor prior to 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

torproject tor

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

A logic error was discovered in the implementation of the SafeSocks option of Tor, a connection-based low-latency anonymous communication system, which did result in allowing unsafe SOCKS4 traffic to pass For the stable distribution (bullseye), this problem has been fixed in version 04516-1 We recommend that you upgrade your tor packages For ...