Description
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.
For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.
An attacker-supplied image controls the overflowing bytes through its palette.
For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.
An attacker-supplied image controls the overflowing bytes through its palette.
Published:
2026-10-01
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to Imager 1.037 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 01 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tonycoz
Tonycoz imager |
|
| Vendors & Products |
Tonycoz
Tonycoz imager |
Thu, 01 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end. An attacker-supplied image controls the overflowing bytes through its palette. | |
| Title | Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp | |
| Weaknesses | CWE-131 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-10-01T15:08:21.378Z
Reserved: 2026-09-29T11:14:01.536Z
Link: CVE-2026-102505
No data.
Status : Awaiting Analysis
Published: 2026-10-01T14:17:20.237
Modified: 2026-10-01T15:09:04.013
Link: CVE-2026-102505
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:00:10Z
Weaknesses
-
CWE-131
Incorrect Calculation of Buffer Size