Impact
The vulnerability in the Imager Perl module allows a reader function to access data beyond the bounds of the EXIF block because the start offset of an IFD entry is unchecked. This can result in bytes from outside the intended area being returned to the caller, potentially exposing sensitive data or causing a crash when the process attempts to read invalid memory. The weakness is an instance of out‑of‑bounds read (CWE‑125).
Affected Systems
Perl Imager implementations from version 0.45_02 up to, but not including, 1.035 are affected. Versions prior to 1.035 store the start offset as a signed integer, while versions 1.033 and later use unsigned types that still permit wrapping on 32‑bit platforms, allowing the flaw to persist until the upgrade to 1.035. The affected module is used in Perl applications that process image files via Imager->read().
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity, and the EPSS score is less than 1% while the vulnerability is not listed in the CISA KEV catalog. The vulnerability could be targeted through any component that accepts user‑supplied image data. An attacker can craft an image whose EXIF block contains entries that read from outside the block, enabling the extraction of unintended bytes or subjecting the host to a crash. The exploit is relatively straightforward once a vulnerable version is in use and does not require additional privileges, making it a low‑effort risk for affected deployments.
OpenCVE Enrichment