Logic Error in Tor's SafeSocks Feature Affects User Privacy
CVE-2023-23589

6.5MEDIUM

Key Information:

Vendor

Torproject

Status
Vendor
CVE Published:
14 January 2023

What is CVE-2023-23589?

A logic error in the SafeSocks feature of the Tor software allows the usage of the insecure SOCKS4 protocol instead of the safer SOCKS4a protocol. This flaw can potentially expose users to privacy risks by enabling unsafe network connections, compromising the core purpose of the Tor network, which is to provide anonymity and security for users. Users should immediately update to the latest version to mitigate these risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.