Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia: 2020-0285 Moderate: Ruby Buffer Overflow Exposes Data

mageia
Calendar Grey July 7, 2020
Dist Mageia Esm H88
Recent upgrades to Ruby libraries address a security flaw in Mageia 7, which could potentially reveal sensitive information.
Updated ruby packages fix security vulnerability: An issue was discovered in Ruby through 2.5.7

Summary

Updated ruby packages fix security vulnerability:
An issue was discovered in Ruby through 2.5.7. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter (CVE-2020-10933).

References

- https://bugs.mageia.org/show_bug.cgi?id=26409

- https://www.ruby-lang.org/en/news/2020/03/31/heap-exposure-in-socket-cve-2020-10933/

- https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-5-8-released/

- https://www.cve.org/CVERecord?id=CVE-2020-10933

Resolution

SRPMS

- 7/core/ruby-2.5.8-21.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 07 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0285.html
Type: security
CVE: CVE-2020-10933

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here