SB2017112140 - Memory leak in varnish (Alpine package)
Published: November 21, 2017
Security Bulletin ID
SB2017112140
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2017-8807)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due memory leak in the vbf_stp_error() function in bin/varnishd/cache/cache_fetch.c. A remote attacker can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=67b7be458895eb0d8faab3d9b232ec040e11ef26
- https://git.alpinelinux.org/aports/commit/?id=2fa274fe2c593821cb7d12715f6cd77210ee6348
- https://git.alpinelinux.org/aports/commit/?id=6de195054a46f2c336e6928317843c55e74fc1f0
- https://git.alpinelinux.org/aports/commit/?id=784f03748a63ed8dec1d2de19bde5e67779d674b
- https://git.alpinelinux.org/aports/commit/?id=7bd56d3d21028471bc6916a522fb6d369cafb692
- https://git.alpinelinux.org/aports/commit/?id=197458f95715a3d3cc12e0d91dbc9204d0363e30
- https://git.alpinelinux.org/aports/commit/?id=336cc11a149e0b1e44bf74c1ba3fa8aa340a828f
- https://git.alpinelinux.org/aports/commit/?id=4f87e60fcf1f3f574759a4efda4ad5a5bffd04e2
- https://git.alpinelinux.org/aports/commit/?id=6813958dd2f4a84778a0540695744cc722d5861e