Bugzilla – Bug 1135418
VUL-0: CVE-2019-11037: php7-imagick: out-of-bounds write to memory in ImagickKernel:fromMatrix() leading to possible crash and DoS
Last modified: 2020-01-16 12:41:00 UTC
CVE-2019-11037 An out-of-bounds write to memory has been found in PHP imagick extension versions between 3.3.0 - 3.4.4 in function ImagickKernel::fromMatrix() leading to possible crash and DoS. Upstream bug: https://bugs.php.net/bug.php?id=77791 References: https://bugzilla.redhat.com/show_bug.cgi?id=1708570 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11037 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11037.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11037 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MQ7WJA25YF2R2LRALK4QEYWUHHJPSUD/ https://github.com/CVEProject/cvelist/pull/1964 https://bugs.php.net/bug.php?id=77791 http://www.securityfocus.com/bid/108292 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BU66V7QJKD32RXLY5J7Z5NZH4V3VV524/
This is an autogenerated message for OBS integration: This bug (1135418) was mentioned in https://build.opensuse.org/request/show/703690 Factory / php7-imagick
This is an autogenerated message for OBS integration: This bug (1135418) was mentioned in https://build.opensuse.org/request/show/758133 15.1+Backports:SLE-12+Backports:SLE-15-SP1 / php7-imagick
openSUSE-SU-2020:0014-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1135418 CVE References: CVE-2019-11037 Sources used: openSUSE Leap 15.1 (src): php7-imagick-3.4.4-lp151.8.3.1 openSUSE Backports SLE-15-SP1 (src): php7-imagick-3.4.4-bp151.2.3.1
openSUSE-SU-2020:0014-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1135418 CVE References: CVE-2019-11037 Sources used: openSUSE Leap 15.1 (src): php7-imagick-3.4.4-lp151.8.3.1 openSUSE Backports SLE-15-SP1 (src): php7-imagick-3.4.4-bp151.2.3.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): php7-imagick-3.4.4-5.1
all done. Closing