Impact
The flaw in Imager for Perl versions prior to 1.036 allows an attacker to read uninitialised heap memory when a paletted image contains pixel indices that exceed the defined colour map. The library’s TGA reader accepts indices that are equal to the colour map count, returning the first uninitialised palette entry; during RGB conversion it also reads from a buffer that has not been fully initialised. When an attacker supplies a crafted image and the application reads or converts it, data from the process heap can be exposed through the returned pixel values.
Affected Systems
Any system that uses Imager for Perl with a version older than 1.036 is vulnerable. This includes distributions that ship the older library, legacy Perl image‑processing applications, and bespoke scripts that depend on Imager to parse user‑supplied images. The vulnerability is active as long as the library is in use and no patch is applied.
Risk and Exploitability
The risk is limited to information disclosure; the vulnerability does not modify program state or provide execution control. The CVSS score of 5.5 reflects a moderate severity, aligning with the information‑disclosure nature of the flaw. An attacker must be able to deliver a crafted image to a running Imager instance, which can be feasible in web services or applications that accept image uploads. The EPSS score of <1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, indicating no widespread exploitation yet. Nonetheless, because it can leak arbitrary heap contents, it should be considered a moderate‑to‑high risk for exposed services and remains exploit‑editable through simple file injection.
OpenCVE Enrichment