vbfstperror in bin/varnishd/cache/cachefetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFPGetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
[
{
"source": "https://github.com/varnishcache/varnish-cache/commit/176f8a075a963ffbfa56f1c460c15f6a1a6af5a7",
"target": {
"function": "vbf_stp_error",
"file": "bin/varnishd/cache/cache_fetch.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2017-8807-54507ce7",
"signature_type": "Function",
"digest": {
"length": 2552.0,
"function_hash": "317635809142638776188580053458899665848"
}
},
{
"source": "https://github.com/varnishcache/varnish-cache/commit/176f8a075a963ffbfa56f1c460c15f6a1a6af5a7",
"target": {
"file": "bin/varnishd/cache/cache_fetch.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2017-8807-db9d9e86",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"35752772080807146568775274854838049175",
"62009287341324849338652974456371337353",
"297563870909354190281146502171842406048",
"182442623255090597664454248417396896307"
]
}
}
]