Back

CRITICAL

Out of bounds memory write in PHP Imagick extension

Published May 3, 2019

Description

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.

Affected products

Remediation

Red Hat statement

This vulnerability does not affect the php55-php-pecl-imagick package shipped in OpenShift Container Platform 3.4 as it does not contain the vulnerable code. The vulnerable source file, imagickkernel_class.c, was added to php-imagick in version 3.3.0. OpenShift Container Platform ships version 3.1.2 and does not contain this source file.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner php
Published May 3, 2019
Updated Sep 16, 2024
Reserved Apr 9, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 4, 2019