CVE-2019-11037
low-risk
Published 2019-05-03
In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.
Do I need to act?
~
1.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.9/10
Medium
LOCAL
/ HIGH complexity
Affected Products (1)
Imagick
Affected Vendors
References (22)
Mailing List
https://bugs.php.net/bug.php?id=77791
Mailing List
https://bugs.php.net/bug.php?id=77791
and 2 more references
21
/ 100
low-risk
Severity
13/34 · Low
Exploitability
3/34 · Minimal
Exposure
5/34 · Minimal