vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade varnish | Nov 23, 2017 | Nov 16, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 16, 2017 |
| Debian | — | Upgrade varnish | Dec 5, 2017 | Nov 15, 2017 |
| Freebsd | — | Upgrade varnish5Upgrade varnish4 | Dec 2, 2017 | Dec 2, 2017 |
| Ubuntu | — | Upgrade libvarnishapi1 (Ubuntu Pro)Upgrade varnish (Ubuntu Pro) | Mar 22, 2023 | Nov 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub