PT-2026-95395 · Cpan · Imager For Perl

·

CVE-2026-93018

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Imager for Perl versions prior to 1.036
Description Reading a paletted image with pixel indexes that exceed its colour map in the i gpix p() and i glin p() functions leads to the disclosure of uninitialised heap memory. The TGA reader stores pixel indexes without validating them against the colour map. In i gpix p(), an index equal to the count reads the first unpopulated entry, which is then returned by getpixel(). In i glin p(), the palette-to-RGB conversion process utilizes an uninitialised buffer, causing pixels in the converted image to contain previous heap contents. An attacker can disclose process heap memory by providing a malicious image via Imager->read() and subsequently fetching its pixels or converting the image to RGB.
Recommendations Update to version 1.036 or later.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93018
GHSA-J7V7-CM4G-VRGF

Affected Products

Imager For Perl