Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11037

Опубликовано: 03 мая 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 4.9

Описание

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

РелизСтатусПримечание
bionic

released

3.4.3~rc2-2ubuntu4.1
cosmic

ignored

end of life
devel

not-affected

3.7.0-2
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

released

3.4.3~rc2-2ubuntu4.1
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

3.7.0-2
esm-apps/xenial

released

3.4.0~rc6-1ubuntu3+esm1

Показывать по

EPSS

Процентиль: 78%
0.01178
Низкий

7.5 High

CVSS2

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 4.9
nvd
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

CVSS3: 4.9
debian
почти 7 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing ...

suse-cvrf
около 6 лет назад

Security update for php7-imagick

CVSS3: 9.8
github
больше 3 лет назад

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

EPSS

Процентиль: 78%
0.01178
Низкий

7.5 High

CVSS2

4.9 Medium

CVSS3