Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11037

Опубликовано: 04 мая 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

Отчет

This vulnerability does not affect the php55-php-pecl-imagick package shipped in OpenShift Container Platform 3.4 as it does not contain the vulnerable code. The vulnerable source file, imagickkernel_class.c, was added to php-imagick in version 3.3.0. OpenShift Container Platform ships version 3.1.2 and does not contain this source file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.4php55-php-pecl-imagickNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1708570php-imagick: out-of-bounds write to memory in ImagickKernel::fromMatrix() leading to possible crash and DoS

EPSS

Процентиль: 78%
0.01178
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 4.9
nvd
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 4.9
debian
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing ...

suse-cvrf
около 6 лет назад

Security update for php7-imagick

CVSS3: 9.8
github
больше 3 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

EPSS

Процентиль: 78%
0.01178
Низкий

7.5 High

CVSS3