CVE Database
/

CVE-2017-8807

Back to search

CVE-2017-8807

Published: Nov 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.

VendorProductVersions

n/a

Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1

affected
Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now