Description
Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries.

Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have known vulnerabilities.
Published: 2026-05-11
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Alien::FreeImage versions through 1.001 for Perl embed the FreeImage library 3.17.0 from 2017, which itself has been the subject of known exploits such as CVE-2015-0852 and CVE-2025-65803. The distribution also bundles additional image libraries that have documented security weaknesses. The presence of these vulnerable components means that any application that loads the module is effectively importing code that may have been subject to exploitation, potentially allowing an attacker to exploit the weaknesses in FreeImage or the other bundled libraries. The weakness is classified as CWE-1395.

Affected Systems

The affected product is Alien::FreeImage 1.001 (and earlier) developed by KMX. Applications that depend on this module, including Perl projects that use image processing or rendering, are at risk. The vulnerability also affects the underlying FreeImage 3.17.0 library and any other embedded image libraries.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, reflecting limited public evidence of active exploitation. However, the listed CVEs for embedded libraries indicate serious potential for remote code execution or privilege escalation once an attacker can supply malicious image data. The likely attack vector is inferred to be the handling of untrusted image files by the library. Because the module bundles known vulnerable binaries, the exploitation would require an attacker to supply a crafted image to the application, after which the embedded library may perform malicious actions or crash the process.

Generated by OpenCVE AI on May 11, 2026 at 20:21 UTC.

Remediation

Vendor Workaround

The latest version of the FreeImage library is 3.18.0 from 2018, which also appears to have serious vulnerabilities. Users are advised to use alternatives.


OpenCVE Recommended Actions

  • Replace Alien::FreeImage with an updated or alternative image handling library that does not embed vulnerable components.
  • Ensure that any image files processed by your application originate only from trusted sources; validate and sanitize input before passing to the library.
  • If a replacement is not immediately possible, isolate the application and monitor for exploitation attempts while planning to upgrade to a vendor‑supplied patch once available.

Generated by OpenCVE AI on May 11, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Kmx
Kmx alien::freeimage
Vendors & Products Kmx
Kmx alien::freeimage

Mon, 11 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have known vulnerabilities.
Title Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries
Weaknesses CWE-1395
References

Subscriptions

Kmx Alien::freeimage
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-05-11T19:04:40.885Z

Reserved: 2026-05-08T07:05:02.847Z

Link: CVE-2022-4988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-11T20:19:35.017

Modified: 2026-05-12T16:48:58.260

Link: CVE-2022-4988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T09:22:25Z

Weaknesses