Information disclosure in Ruby - CVE-2020-10933

 

Information disclosure in Ruby - CVE-2020-10933

Published: July 26, 2020


Vulnerability identifier: #VU31886
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10933
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to BasicSocket#read_nonblock method outputs previous value of the heap instead of copying the requested data. A remote attacker can gain access to sensitive information on the system.


Affected software

Ruby
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Opensuse
Ubuntu
openEuler
Fedora
Red Hat Software Collections
ruby (Alpine package)
rh-ruby25-ruby (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-xmlrpc
rubygem-io-console
rubygem-power_assert
rubygem-did_you_mean
rubygem-bigdecimal
rubygem-openssl
rubygem-json
libruby2.3 (Ubuntu package)
ruby2.3 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby2.5 (Ubuntu package)
ruby-debugsource
ruby-debuginfo
ruby-devel
ruby
ruby-help
ruby-irb
ruby2.5 (Debian package)
rh-ruby26-ruby (Red Hat package)
ruby2.7 (Ubuntu package)
libruby2.7 (Ubuntu package)
rubygems
rubygems-devel
rubygem-psych
rubygem-test-unit
rubygem-minitest
rubygem-rdoc
rubygem-rake
IBM Cloud Foundry Migration Runtime

How to mitigate CVE-2020-10933

Install updates from vendor's website.

Ruby - addressed in versions 2.5.7, 2.6.5
ruby (Alpine package) - addressed in versions 2.5.8-r0, 2.6.6-r2
rh-ruby25-ruby (Red Hat package) - update to 2.5.9-9.el7
IBM Cloud Foundry Migration Runtime - update to 4.1.2
rubygem-net-telnet - update to 0.1.1-105
rubygem-xmlrpc - update to 0.3.0-105
rubygem-io-console - update to 0.4.6-105
rubygem-power_assert - update to 1.1.1-105
rubygem-did_you_mean - update to 1.2.0-105
rubygem-bigdecimal - update to 1.3.4-105
rubygem-openssl - update to 2.1.0-105
rubygem-json - update to 2.1.0-105
libruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
ruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
ruby-debugsource - update to 2.5.1-105
ruby-debuginfo - update to 2.5.1-105
ruby-devel - update to 2.5.1-105
ruby - update to 2.5.1-105
ruby-help - update to 2.5.1-105
ruby-irb - update to 2.5.1-105
ruby2.5 (Debian package) - update to 2.5.5-3+deb10u2
ruby - update to 2.6.6-125.fc31
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
rubygems - update to 2.7.6-105
rubygems-devel - update to 2.7.6-105
rubygem-psych - update to 3.0.2-105
rubygem-test-unit - update to 3.2.7-105
rubygem-minitest - update to 5.10.3-105
rubygem-rdoc - update to 6.0.1-105
rubygem-rake - update to 12.3.0-105

External References

Related Security Bulletins