Security Advisories (5)
CVE-2016-1238 (2016-08-02)

Imager would search the default current directory entry in @INC when searching for file format support modules.

CPANSA-Imager-2014-01 (2014-01-03)

When drawing on an image with an alpha channel where the source minimum is greater than zero, Imager would read from beyond the end of a malloc() allocated buffer. In rare circumstances this could lead to some of the source image not being written to the target image, or possibly to a segmentation fault.

CVE-2007-2459 (2007-05-02)

Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files.

CVE-2006-0053 (2006-04-10)

Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.

CVE-2024-53901 (2024-11-17)

"invalid next size" backtrace on use of trim on certain images

Changes for version 0.27 - 1999-11-23

  • This is a bugfix version mostly, thanks to claes for pointing
  • out the problems - fixed palette saving wasn't working correctly after version 0.24 - rather surprised this didn't crash everything. Also fixed that for t1 fonts the bounding box wasn't being reported unless the font had been used before. This is either a bug in t1lib or a mistake in it's documentation. Another lingering bug since 0.24 what that $img->box() wasn't creating it's default color properly. Added i_tt_text() method and more debuging to the truetype routines.

Modules

Perl extension for Generating 24 bit Images