• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2023-23589
  1. CVEs

CVE-2023-23589

medium
  • Information
  • CPEs
  • Plugins

Description

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

References

https://gitlab.torproject.org/tpo/core/tor/-/commit/a282145b3634547ab84ccd959d0537c021ff7ffc

https://gitlab.torproject.org/tpo/core/tor/-/issues/40730

https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.7/ReleaseNotes

https://www.debian.org/security/2023/dsa-5320

https://lists.fedoraproject.org/archives/list/[email protected]/message/ZMY4FWXYKP3MDXTZ3EJ7XJVGBCKBK2XL/

https://lists.fedoraproject.org/archives/list/[email protected]/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ/

https://lists.debian.org/debian-lts-announce/2023/01/msg00026.html

Details

Source: MITRE

Published: 2023-01-14

Updated: 2023-01-30

Type: NVD-CWE-noinfo

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance