Medium severity6.5NVD Advisory· Published Jan 14, 2023· Updated Jun 17, 2026
CVE-2023-23589
CVE-2023-23589
Description
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*range: <0.4.7.13
- (no CPE)range: <0.4.7.13
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- gitlab.torproject.org/tpo/core/tor/-/commit/a282145b3634547ab84ccd959d0537c021ff7ffcnvdPatchVendor Advisory
- gitlab.torproject.org/tpo/core/tor/-/issues/40730nvdExploitIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00026.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2023/dsa-5320nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMY4FWXYKP3MDXTZ3EJ7XJVGBCKBK2XL/nvd
- security.gentoo.org/glsa/202305-11nvd
News mentions
0No linked articles in our index yet.