CVE-2023-23589: Medium severity tor project tor vulnerability
Published Jan 14, 2023
·Updated
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
Affected Software
6 affected componentsFixes available
debian/tor<=0.3.5.16-1
0.3.5.16-1+deb10u10.4.5.16-10.4.7.13-10.4.8.7-1
torproject Tor<0.4.7.13
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
Jan 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-23589?
CVE-2023-23589 is a vulnerability in Tor before version 0.4.7.13 that allows the unsafe SOCKS4 protocol to be used but not the safe SOCKS4a protocol.
2
What is the severity of CVE-2023-23589?
The severity of CVE-2023-23589 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2023-23589?
Tor versions up to and excluding 0.4.7.13 on Torproject Tor, Debian Debian Linux 10.0 and 11.0, and Fedora 36 and 37 are affected.
4
How can I fix CVE-2023-23589?
To fix CVE-2023-23589, update Tor to version 0.4.7.13 or later.
5
Where can I find more information about CVE-2023-23589?
More information about CVE-2023-23589 can be found in the Tor Project's GitLab repository.