Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-10933
Description:An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.
Test IDs: 1.3.6.1.4.1.25623.1.0.704721   1.3.6.1.4.1.25623.1.1.10.2020.0285  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-10933
Debian Security Information: DSA-4721 (Google Search)
https://www.debian.org/security/2020/dsa-4721
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4TNVTT66VPRMX5UZYSDGSVRXKKDDDU5/




© 1998-2025 E-Soft Inc. All rights reserved.