{"id":"UBUNTU-CVE-2017-8807","details":"vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.","modified":"2026-04-22T12:35:52.005889Z","published":"2017-11-16T02:29:00Z","related":["USN-4824-1"],"upstream":["CVE-2017-8807"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-8807"},{"type":"REPORT","url":"http://varnish-cache.org/security/VSV00002.html"},{"type":"REPORT","url":"https://github.com/varnishcache/varnish-cache/pull/2429"},{"type":"REPORT","url":"https://bugs.debian.org/881808"},{"type":"REPORT","url":"https://github.com/varnishcache/varnish-cache/commit/176f8a075a963ffbfa56f1c460c15f6a1a6af5a7"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2017-8807"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4824-1"}],"affected":[{"package":{"name":"varnish","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/varnish@4.1.1-1ubuntu0.2+esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-1ubuntu0.2+esm1"}]}],"versions":["4.0.3-1","4.1.0-1","4.1.0-2","4.1.1-1","4.1.1-1ubuntu0.2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"libvarnishapi1","binary_version":"4.1.1-1ubuntu0.2+esm1"},{"binary_name":"varnish","binary_version":"4.1.1-1ubuntu0.2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8807.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"low"}]}