See how tonycoz compares to other vendors in security performance
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in igsampffp.
For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.
An attacker-supplied image controls the overflowing bytes through its palette.
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range rawdatachannels value in ireadrawwiol.
Nothing range-checks rawdatachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).
Passing an untrusted rawdatachannels value to Imager->read() triggers an uncatchable exit.
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.
An attacker could craft an image with EXIF data that terminates a worker process.
The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image.