Debian Package Tracker
Register | Log in
Subscribe

libimager-perl

Perl extension for generating 24-bit images

Choose email to subscribe with

general
  • source: libimager-perl (main)
  • version: 1.037+dfsg-2
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: Damyan Ivanov [DMD] – gregor herrmann [DMD] – Dominic Hargreaves [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.012+dfsg-1
  • oldstable: 1.019+dfsg-1
  • stable: 1.027+dfsg-1
  • testing: 1.036+dfsg-1
  • unstable: 1.037+dfsg-2
versioned links
  • 1.012+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.019+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.027+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.036+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.037+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libimager-perl
action needed
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-102504: Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
  • CVE-2026-102505: Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end. An attacker-supplied image controls the overflowing bytes through its palette.
Created: 2026-10-01 Last update: 2026-10-05 22:00
8 security issues in bullseye high

There are 8 open security issues in bullseye.

3 important issues:
  • CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via im_decode_exif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager. Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif_* tag holding adjacent heap bytes instead of an empty string.
  • CVE-2026-73638:
  • CVE-2026-73639:
5 issues postponed or untriaged:
  • CVE-2026-8669: (needs triaging) Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.
  • CVE-2024-53901: (postponed; to be fixed through a stable update) The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image.
  • CVE-2026-13705: (postponed; to be fixed through a stable update) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so a run with data_left / 2 < count <= data_left passes the guard yet consumes 2 * count bytes and reads past the end of the buffer. The 8-bit path is unaffected because there one pixel is one byte. Reading a crafted SGI image through Imager->read triggers the over-read before the parser rejects the malformed image, which can crash the process.
  • CVE-2026-13708: (postponed; to be fixed through a stable update) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without freeing it. Only the final payload is later turned into a Perl scalar and freed, so a JPEG with N such markers leaks the first N-1 payloads on every read. In a long-lived process, such as an upload or thumbnailing service, repeated reads accumulate these leaks and exhaust available memory, a denial of service. The same handler ships bundled in the Imager distribution, where versions before 1.032 are affected and the fix ships in 1.032.
  • CVE-2026-14454: (postponed; to be fixed through a stable update) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
Created: 2026-08-07 Last update: 2026-08-25 01:32
11 low-priority security issues in trixie low

There are 11 open security issues in trixie.

11 issues left for the package maintainer to handle:
  • CVE-2026-8669: (needs triaging) Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.
  • CVE-2026-13705: (needs triaging) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so a run with data_left / 2 < count <= data_left passes the guard yet consumes 2 * count bytes and reads past the end of the buffer. The 8-bit path is unaffected because there one pixel is one byte. Reading a crafted SGI image through Imager->read triggers the over-read before the parser rejects the malformed image, which can crash the process.
  • CVE-2026-13708: (needs triaging) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without freeing it. Only the final payload is later turned into a Perl scalar and freed, so a JPEG with N such markers leaks the first N-1 payloads on every read. In a long-lived process, such as an upload or thumbnailing service, repeated reads accumulate these leaks and exhaust available memory, a denial of service. The same handler ships bundled in the Imager distribution, where versions before 1.032 are affected and the fix ships in 1.032.
  • CVE-2026-14454: (needs triaging) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
  • CVE-2026-19082: (needs triaging) Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via im_decode_exif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager. Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif_* tag holding adjacent heap bytes instead of an empty string.
  • CVE-2026-73638: (needs triaging) Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the EXIF block, and never checks the start offset itself. Where that sum is not the real end of the data, the check passes with the entry starting outside the block. Through 1.032 `entry->offset` is a plain int, so on the usual two's-complement implementations an offset with the high bit set converts to negative and the sum can land back inside the block. From 1.033 the field is a size_t and the addition wraps only where size_t is 32 bits. The IFD's own start offset is checked the same way and wraps where unsigned long is 32 bits, which includes 64-bit Windows. Any caller of Imager->read() on an attacker-supplied image may receive EXIF tags holding bytes from outside the block, or crash the process.
  • CVE-2026-73639: (needs triaging) Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row. The same reader ships bundled in the Imager distribution. Reading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process.
  • CVE-2026-93018: (needs triaging) Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it. i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents. Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.
  • CVE-2026-93019: (needs triaging) Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
  • CVE-2026-102504: (needs triaging) Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
  • CVE-2026-102505: (needs triaging) Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end. An attacker-supplied image controls the overflowing bytes through its palette.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-05-15 Last update: 2026-10-05 22:00
testing migrations
  • excuses:
    • Migration status for libimager-perl (1.036+dfsg-1 to 1.037+dfsg-2): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for libimager-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libimager-qrcode-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libwww-mechanize-chrome-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Reproducibility check waiting for results on amd64 - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libi/libimager-perl.html
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-05] Accepted libimager-perl 1.037+dfsg-2 (source) into unstable (gregor herrmann)
  • [2026-10-02] Accepted libimager-perl 1.037+dfsg-1 (source) into experimental (gregor herrmann)
  • [2026-09-21] libimager-perl 1.036+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-18] Accepted libimager-perl 1.036+dfsg-1 (source) into unstable (gregor herrmann)
  • [2026-08-25] libimager-perl 1.035+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-19] Accepted libimager-perl 1.035+dfsg-1 (source) into unstable (gregor herrmann)
  • [2026-08-12] Accepted libimager-perl 1.034+dfsg-2 (source) into unstable (gregor herrmann)
  • [2026-08-07] Accepted libimager-perl 1.034+dfsg-1 (source) into unstable (gregor herrmann)
  • [2026-07-15] libimager-perl 1.033+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-12] Accepted libimager-perl 1.033+dfsg-1 (source) into unstable (gregor herrmann)
  • [2026-07-09] libimager-perl 1.032+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-06] Accepted libimager-perl 1.032+dfsg-1 (source) into unstable (gregor herrmann)
  • [2026-05-25] libimager-perl 1.031+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-15] Accepted libimager-perl 1.031+dfsg-1 (source) into unstable (Samuel Young) (signed by: gregor herrmann)
  • [2026-04-18] libimager-perl 1.030+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-15] Accepted libimager-perl 1.030+dfsg-1 (source) into unstable (Samuel Young) (signed by: gregor herrmann)
  • [2025-10-13] libimager-perl 1.029+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-10] Accepted libimager-perl 1.029+dfsg-1 (source) into unstable (gregor herrmann)
  • [2025-10-09] libimager-perl 1.028+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-06] Accepted libimager-perl 1.028+dfsg-1 (source) into unstable (gregor herrmann)
  • [2025-03-19] libimager-perl 1.027+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-16] Accepted libimager-perl 1.027+dfsg-1 (source) into unstable (gregor herrmann)
  • [2024-11-25] libimager-perl 1.025+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-23] Accepted libimager-perl 1.025+dfsg-1 (source) into unstable (gregor herrmann)
  • [2024-09-17] libimager-perl 1.024+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-09-15] Accepted libimager-perl 1.024+dfsg-2 (source) into unstable (gregor herrmann)
  • [2024-05-03] libimager-perl 1.024+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-13] Accepted libimager-perl 1.024+dfsg-1 (source) into unstable (gregor herrmann)
  • [2024-01-23] libimager-perl 1.023+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-20] Accepted libimager-perl 1.023+dfsg-1 (source) into unstable (gregor herrmann)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.035+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing