Imager

Imager

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 01.10.2026 13:11:38
  • Zuletzt bearbeitet 08.10.2026 13:17:42

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with...

  • EPSS 0.61%
  • Veröffentlicht 18.09.2026 13:58:12
  • Zuletzt bearbeitet 18.09.2026 18:18:17

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative....

  • EPSS 0.18%
  • Veröffentlicht 18.09.2026 13:57:37
  • Zuletzt bearbeitet 22.09.2026 19:16:57

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as po...

  • EPSS 0.18%
  • Veröffentlicht 17.09.2026 21:18:59
  • Zuletzt bearbeitet 22.09.2026 19:16:44

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still ...

  • EPSS 0.18%
  • Veröffentlicht 17.09.2026 21:18:51
  • Zuletzt bearbeitet 22.09.2026 19:16:44

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the EXIF block, an...

  • EPSS 1.67%
  • Veröffentlicht 24.04.2008 05:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:46

Buffer overflow in Imager 0.42 through 0.63 allows attackers to cause a denial of service (crash) via an image based fill in which the number of input channels is different from the number of output channels.