PT-2026-95396 · Cpan · Imager For Perl
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Imager for Perl versions prior to 1.036
Description
Processing a TGA file with a colour map length of 32768 or more triggers an uncatchable process exit when using the
Imager->read() function. This occurs because the reader unpacks the two-byte colour map length into a signed short, causing values of 32768 or more to be interpreted as negative. The tga palette read() function then casts this negative value to size t, leading mymalloc() to request an excessively large memory allocation near SIZE MAX. When this allocation fails, the allocator calls exit(3), terminating the process.Recommendations
Update Imager for Perl to version 1.036 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imager For Perl