Impact
The vulnerability centers on the Perl module Image::EPEG, which bundles an obsolete Epeg 0.9.0 library last updated in 2004. Because that library has not been maintained for nearly two decades, it may contain unpatched security weaknesses that an attacker could exploit. The issue is classified as CWE‑1104, reflecting the use of legacy, unsupported code in a production environment. Consequently, systems relying on this module face an uncertain risk of undisclosed vulnerabilities that could undermine application security.
Affected Systems
Any installation of TOKUHIROM Image::EPEG up through version 0.15 is affected. Applications that import this module for JPEG thumbnail creation, especially those that accept user‑supplied image uploads, are at potential risk. The problem does not extend beyond these specific modules or their dependent code.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. Based on the description, it is inferred that a malicious JPEG file could trigger a flaw in the embedded legacy library. The risk remains uncertain due to the absence of an official patch, but the low exploitation probability and the fact that the component is no longer maintained lessen the immediate threat profile.
OpenCVE Enrichment