Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.

copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via im_decode_exif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager.

Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif_* tag holding adjacent heap bytes instead of an empty string.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug in Imager’s copy_string_tags routine incorrectly calculates the length of zero‑count ASCII EXIF entries as –1, causing a call to strlen() that reads past the intended buffer and copies arbitrary heap data into the returned tag. An attacker can supply a crafted image that, when processed by Imager->read, produces an exif_* field containing data from adjacent heap memory instead of an empty string. The flaw does not provide code execution or privilege escalation, but it can leak portions of process memory that may contain sensitive information. The likely attack vector is an application that accepts external images and passes them directly to Imager->read.

Affected Systems

The vulnerability affects the TONYC Imager library for Perl, specifically all releases from 0.45_02 through 1.033 inclusive. Both the JPEG and the Imager::File::WEBP distribution are impacted because they use the same EXIF parsing path. The fixed version is 1.034 and later.

Risk and Exploitability

There is no EPSS score available and the flaw is not listed in CISA’s KEV catalog. The CVSS score of 7.5 indicates moderate to high severity. The vulnerability can expose portions of memory depending on the data adjacent to the heap byte area. An attacker who can control the image payload can read arbitrary heap data that may contain confidential information or secret keys. The exploit requires only that the target application invoke Imager->read on an attacker‑supplied image, making exploitation straightforward and not dependent on additional system privileges.

Generated by OpenCVE AI on August 7, 2026 at 20:42 UTC.

Remediation

Vendor Solution

Upgrade to Imager 1.034 or later.


OpenCVE Recommended Actions

  • Upgrade Imager to version 1.034 or later.
  • If upgrading is not immediately possible, apply the vendor’s patch commit from https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe to the source before building Imager.
  • Modify your application to avoid processing EXIF data from untrusted images or strip EXIF tags before calling Imager->read, thereby limiting exposure to this over‑read issue.

Generated by OpenCVE AI on August 7, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tonyc
Tonyc imager
Vendors & Products Tonyc
Tonyc imager

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via im_decode_exif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager. Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif_* tag holding adjacent heap bytes instead of an empty string.
Title Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-07T20:13:18.224Z

Reserved: 2026-08-06T11:48:54.170Z

Link: CVE-2026-19082

cve-icon Vulnrichment

Updated: 2026-08-07T18:22:59.802Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:00:05Z

Weaknesses