Impact
The vulnerability in Imager for Perl occurs when a raw image file contains an out‑of‑range raw_datachannels value. The code path that reads the raw image does not enforce any bounds on raw_datachannels, so a negative or excessively large value causes an oversized buffer allocation. When the allocator cannot fulfill the request, the library calls the standard exit routine, terminating the Perl process. This failure cannot be caught or recovered by application code, resulting in a sudden denial of service. The weakness is classified as integer overflow and out‑of‑range memory allocation.
Affected Systems
Any installation of the Imager Perl module with a version earlier than 1.037 is affected. The vulnerability applies to all products that rely on Imager for rendering or processing raw image files, including web applications, image conversion utilities, or batch image processing scripts that use Imager->read() on externally supplied files. The fix is available in Imager 1.037 and later releases.
Risk and Exploitability
The lack of a CVSS score and EPSS rating means the risk is not quantified in the standard metrics, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local or remote depending on who can supply a raw image file to the affected application; it requires the ability to control the raw_datachannels field in the image header. The impact is limited to a process crash, which can lead to service interruption but does not provide arbitrary code execution or data exfiltration. Therefore the overall risk is moderate, with a high likelihood that a system relying on Imager will be vulnerable if no mitigation is applied.
OpenCVE Enrichment