First published: Fri May 03 2019(Updated: )
In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.
Credit: security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
PHP imagick | >=3.3.0<=3.4.4 | |
debian/php-imagick | 3.4.4+php8.0+3.4.4-2+deb11u2 3.7.0-4 3.7.0-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.