CVE-2019-11037

EUVD-2019-2745
In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
phpCNA
4.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
phpimagick
3.3.0 ≤
𝑥
≤ 3.4.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-imagick
bookworm
3.7.0-4
fixed
bullseye
3.4.4+php8.0+3.4.4-2+deb11u2
fixed
jessie
not-affected
sid
3.7.0-5
fixed
trixie
3.7.0-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-imagick
bionic
Fixed 3.4.3~rc2-2ubuntu4.1
released
cosmic
ignored
disco
ignored
eoan
ignored
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
not-affected
xenial
Fixed 3.4.0~rc6-1ubuntu3+esm1
released