DSA-4576-1 php-imagick -- security update

Related Vulnerabilities: CVE-2019-11037  

An out-of-bounds write vulnerability was discovered in php-imagick, a PHP extension to create and modify images using the ImageMagick API, which could result in denial of service, or potentially the execution of arbitrary code. For the oldstable distribution (stretch), this problem has been fixed in version 3.4.3~rc2-2+deb9u1. We recommend that you upgrade your php-imagick packages. For the detailed security status of php-imagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-imagick

Debian Security Advisory

DSA-4576-1 php-imagick -- security update

Date Reported:
25 Nov 2019
Affected Packages:
php-imagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 928420.
In Mitre's CVE dictionary: CVE-2019-11037.
More information:

An out-of-bounds write vulnerability was discovered in php-imagick, a PHP extension to create and modify images using the ImageMagick API, which could result in denial of service, or potentially the execution of arbitrary code.

For the oldstable distribution (stretch), this problem has been fixed in version 3.4.3~rc2-2+deb9u1.

We recommend that you upgrade your php-imagick packages.

For the detailed security status of php-imagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-imagick