CVE-2017-8807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
16/11/2017
Last modified:
20/04/2025

Description

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:varnish-cache:varnish:*:*:*:*:*:*:*:* 4.1.0 (including) 4.1.9 (excluding)
cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* 5.0.0 (including) 5.2.1 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*