Impact
The bug in Imager’s copy_string_tags routine incorrectly calculates the length of zero‑count ASCII EXIF entries as –1, causing a call to strlen() that reads past the intended buffer and copies arbitrary heap data into the returned tag. An attacker can supply a crafted image that, when processed by Imager->read, produces an exif_* field containing data from adjacent heap memory instead of an empty string. The flaw does not provide code execution or privilege escalation, but it can leak portions of process memory that may contain sensitive information. The likely attack vector is an application that accepts external images and passes them directly to Imager->read.
Affected Systems
The vulnerability affects the TONYC Imager library for Perl, specifically all releases from 0.45_02 through 1.033 inclusive. Both the JPEG and the Imager::File::WEBP distribution are impacted because they use the same EXIF parsing path. The fixed version is 1.034 and later.
Risk and Exploitability
There is no EPSS score available and the flaw is not listed in CISA’s KEV catalog. The CVSS score of 7.5 indicates moderate to high severity. The vulnerability can expose portions of memory depending on the data adjacent to the heap byte area. An attacker who can control the image payload can read arbitrary heap data that may contain confidential information or secret keys. The exploit requires only that the target application invoke Imager->read on an attacker‑supplied image, making exploitation straightforward and not dependent on additional system privileges.
OpenCVE Enrichment