VDB

ALPINE-CVE-2017-8807

ALPINE-CVE-2017-8807 PUBLISHED CVSS 9.100000381469727 CRITICAL

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.7varnish4.1.2-r0, 4.1.0, 4.1.0
Alpine:v3.14varnish4.1.0-r1, 2.1.5-r0, 3.0.0-r0
Alpine:v3.11varnish5.1.2-r0, 3.0.3-r2, 3.0.2-r5
Alpine:v3.20varnish3.0.3-r0, 4.1.0, 4.1.0
Alpine:v3.10varnish4.1.1-r0, 4.1.2-r1, 4.1.2-r2
Alpine:v3.3varnish0, 2.1.5-r0, 3.0.0-r0
Alpine:v3.21varnish3.0.4-r4, 2.1.5-r0, 2.1.5-r0
Alpine:v3.15varnish3.0.4-r3, 3.0.2-r3, 3.0.5-r0
Alpine:v3.24varnish0, 4.1.0, 4.1.0
Alpine:v3.19varnish4.1.0-r2, 0, 2.1.5-r0
Alpine:v3.18varnish3.0.3-r2, 5.2.0-r0, 5.1.2-r0
Alpine:v3.16varnish4.1.2-r2, 3.0.3-r1, 3.0.3-r2
Alpine:v3.22varnish3.0.3-r2, 3.0.4-r0, 3.0.2-r2
Alpine:v3.12varnish3.0.4-r4, 0, 2.1.5-r0
Alpine:v3.23varnish3.0.0-r0, 2.1.5-r0, 0
Alpine:v3.5varnish4.0.2-r0, 2.1.5-r0, 3.0.2-r1
Alpine:v3.4varnish4.1.0, 4.1.0, 0
Alpine:v3.13varnish4.1.0-r1, 4.1.0-r2, 4.1.1-r0
Alpine:v3.6varnish4.1.0, 4.1.0, 0
Alpine:v3.8varnish3.0.0-r2, 3.0.0-r1, 0

…and 2 more

Timeline

  • Nov 16, 2017 CVE Published
  • Jul 8, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›