ZeroHour

CVE-2020-10933

PoC
CVSS 3.1
5.3 medium
EPSS
3%p84
Published
()
Modified
Description

An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.

Vendors
ruby-langfedoraprojectdebian
Products
ruby, fedora, debian linux
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.