CyberRota Analysis
AI-GeneratedImager versions prior to 1.036 are vulnerable to a denial-of-service condition when processing TGA files with a color map length of 32768 or more, leading to an uncatchable exit due to improper handling of the color map length. This vulnerability can be exploited by supplying a malicious TGA file, causing the application to terminate unexpectedly. Developers and organizations using Imager for image processing should prioritize addressing this issue to prevent potential disruptions in their applications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.