SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10933

This may expose possibly sensitive data from the interpreter.

MEDIUM 5.3EPSS 2.56%

Does this matter?

Lower severity and a low EPSS score (2.56%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.56% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-908
Affected
ruby-lang/ruby · fedoraproject/fedora · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.