Impact
Imager versions earlier than 1.036 interpret the two‑byte colour map length as a signed short; a value of 32768 or higher becomes negative. The value is then cast to size_t and passed to mymalloc(), requesting a size close to SIZE_MAX. The allocation fails, causing Imager to call exit(3). As a result, any application that reads such a TGA image via Imager->read() will terminate abruptly, leading to a denial of service. The vulnerability is exploitable by supplying a crafted TGA file to the application.
Affected Systems
The flaw affects the Perl Imager module released by TONYC, specifically all editions before version 1.036. Any system that installs and uses these earlier versions and processes TGA images is vulnerable.
Risk and Exploitability
The CVSS score is 9.1 and the EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, any application that reads such a TGA image via Imager->read() triggers an uncatchable exit. An attacker who can supply an image (e.g., via file upload, local file manipulation, or phishing) can crash an application deterministically. Because the exit is uncatchable, the impact is a complete loss of service for the affected process. The risk is effectively high for availability, though there is no direct code‑execution or data‑exposure risk.
OpenCVE Enrichment