vbfstperror in bin/varnishd/cache/cachefetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFPGetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
[ { "source": "https://github.com/varnishcache/varnish-cache/commit/176f8a075a963ffbfa56f1c460c15f6a1a6af5a7", "deprecated": false, "target": { "file": "bin/varnishd/cache/cache_fetch.c", "function": "vbf_stp_error" }, "digest": { "function_hash": "317635809142638776188580053458899665848", "length": 2552.0 }, "id": "CVE-2017-8807-54507ce7", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://github.com/varnishcache/varnish-cache/commit/176f8a075a963ffbfa56f1c460c15f6a1a6af5a7", "deprecated": false, "target": { "file": "bin/varnishd/cache/cache_fetch.c" }, "digest": { "line_hashes": [ "35752772080807146568775274854838049175", "62009287341324849338652974456371337353", "297563870909354190281146502171842406048", "182442623255090597664454248417396896307" ], "threshold": 0.9 }, "id": "CVE-2017-8807-db9d9e86", "signature_type": "Line", "signature_version": "v1" } ]