VDB

GCVE-110-MAGEIA-2020-285

GCVE-110-MAGEIA-2020-285
Advisory Published
Vulnetix · Advisory published July 7, 2020
Updated ruby packages fix security vulnerability: An issue was discovered in Ruby through 2.5.7. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter (CVE-2020-10933).

Affected Products

VendorProductVersionsPlatforms
Mageiaruby0 (affected), 2.5.8-21.mga7 (unaffected)

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›