Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11037

Опубликовано: 03 мая 2019
Источник: nvd
CVSS3: 4.9
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:php:imagick:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.4.4 (включая)

EPSS

Процентиль: 78%
0.01178
Низкий

4.9 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 7.5
redhat
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 4.9
debian
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing ...

suse-cvrf
около 6 лет назад

Security update for php7-imagick

CVSS3: 9.8
github
больше 3 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

EPSS

Процентиль: 78%
0.01178
Низкий

4.9 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787
CWE-787