CVE-2019-11037

low-risk
Published 2019-05-03

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

Do I need to act?

~
1.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.9/10 Medium
LOCAL / HIGH complexity

Affected Products (1)

Imagick

Affected Vendors

Php
21
/ 100
low-risk
Severity 13/34 · Low
Exploitability 3/34 · Minimal
Exposure 5/34 · Minimal