Impact
Imager::File::PNG versions earlier than 1.004 for Perl contain a buffer overflow that occurs when parsing PNG files with a tRNS transparency chunk. The read_direct8() routine expands a transparency channel but still allocates a buffer based solely on the original channel count, causing libpng to write beyond the end of the allocated memory. This overflow corrupts the heap and can crash the Imager process, presenting a denial‑of‑service risk. The overflow also grants an attacker the opportunity to overwrite adjacent memory, which, while not explicitly documented, is inferred as a potential vector for more severe exploitation if the process environment permitted it.
Affected Systems
Vendors are Imager (Perl image processing library) and its bundled Imager-File-PNG distribution. Affected versions are Imager-File-PNG 1.003 and any release before 1.004, and any Imager package that includes the old bundled Imager-File-PNG prior to 1.035. Versions 1.004 of Imager-File-PNG or newer, and Imager 1.035 or newer, contain the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, while the EPSS score of less than 1% indicates a very low probability of exploitation currently. The vulnerability is not in CISA’s KEV catalog, so no mass‑distributed attacks are known. An attacker would need to supply a specially crafted PNG with a tRNS chunk that is processed by an application using the vulnerable Imager build. The denial‑of‑service impact is clearly supported. Inferred from the buffer overflow, the risk of privilege escalation or remote code execution exists if the attacker can influence the process environment or memory layout, but this has not been demonstrated. Because of the potential for denial of service on any application that loads arbitrary PNGs, the risk remains significant.
OpenCVE Enrichment