PT-2023-19061 · Tor+1 · Tor+1

Published

2023-01-13

·

Updated

2025-05-12

·

CVE-2023-23589

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.7.13
Description The issue is related to a logic error in the SafeSocks option, where the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol.
Recommendations For versions prior to 0.4.7.13, update to version 0.4.7.13 or later to resolve the issue.

Exploit

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1040
ALT-PU-2023-1190
ALT-PU-2025-6362
CVE-2023-23589
DLA-3286-1
DSA-5320-1
MGASA-2023-0017
ROSA-SA-2023-2219

Affected Products

Alt Linux
Tor