CVE-2023-23589
published 2023-01-14CVE-2023-23589: The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.83%
53.5th percentile
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tor | < tor 0.4.7.13-1 (bookworm) | tor 0.4.7.13-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| torproject | tor | < 0.4.7.13 | 0.4.7.13 |
| torproject | tor | >= 0 < 0.4.5.16-1 | 0.4.5.16-1 |
| torproject | tor | >= 0 < 0.4.7.13-1 | 0.4.7.13-1 |
| torproject | tor | >= 0 < 0.4.7.13-1 | 0.4.7.13-1 |
| torproject | tor | >= 0 < 0.4.7.13-1 | 0.4.7.13-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-23589: tor - The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsaf...
vendor_debian·2023·CVSS 6.5
CVE-2023-23589 [MEDIUM] CVE-2023-23589: tor - The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsaf...
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
Scope: local
bookworm: resolved (fixed in 0.4.7.13-1)
bullseye: resolved (fixed in 0.4.5.16-1)
forky: resolved (fixed in 0.4.7.13-1)
sid: resolved (fixed in 0.4.7.13-1)
trixie: resolved (fixed in 0.4.7.13-1)
GHSA
GHSA-6wqq-m34g-chqp: The SafeSocks option in Tor before 0
ghsa_unreviewed·2023-01-14
CVE-2023-23589 [MEDIUM] CWE-693 GHSA-6wqq-m34g-chqp: The SafeSocks option in Tor before 0
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
OSV
CVE-2023-23589: The SafeSocks option in Tor before 0
osv·2023-01-14·CVSS 6.5
CVE-2023-23589 [MEDIUM] CVE-2023-23589: The SafeSocks option in Tor before 0
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.torproject.org/tpo/core/tor/-/commit/a282145b3634547ab84ccd959d0537c021ff7ffchttps://gitlab.torproject.org/tpo/core/tor/-/issues/40730https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.7/ReleaseNoteshttps://lists.debian.org/debian-lts-announce/2023/01/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMY4FWXYKP3MDXTZ3EJ7XJVGBCKBK2XL/https://security.gentoo.org/glsa/202305-11https://www.debian.org/security/2023/dsa-5320https://gitlab.torproject.org/tpo/core/tor/-/commit/a282145b3634547ab84ccd959d0537c021ff7ffchttps://gitlab.torproject.org/tpo/core/tor/-/issues/40730https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.7/ReleaseNoteshttps://lists.debian.org/debian-lts-announce/2023/01/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMY4FWXYKP3MDXTZ3EJ7XJVGBCKBK2XL/https://security.gentoo.org/glsa/202305-11https://www.debian.org/security/2023/dsa-5320
2023-01-14
Published