MGASA-2017-0435

Source
https://advisories.mageia.org/MGASA-2017-0435.html
Import Source
https://advisories.mageia.org/MGASA-2017-0435.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0435
Related
Published
2017-12-01T23:13:21Z
Modified
2017-12-01T22:46:48Z
Summary
Updated varnish packages fix security vulnerability
Details

vbfstperror in bin/varnishd/cache/cachefetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFPGetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects. (CVE-2017-8807)

References
Credits

Affected packages

Mageia:6 / varnish

Package

Name
varnish
Purl
pkg:rpm/mageia/varnish?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-3.2.mga6

Ecosystem specific

{
    "section": "core"
}