CVE-2023-23589: Debian Linux

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Fedoraproject Fedora: version 36 only; version 37 only
  • Torproject Tor: before 0.4.7.13 (fixed in 0.4.7.13)

Published 2023-01-14. Last modified 2026-06-17.