Security Advisories (9)
CVE-2016-1238 (2016-08-02)

Imager would search the default current directory entry in @INC when searching for file format support modules.

CVE-2008-1928 (2008-04-24)

Buffer overflow in Imager 0.42 through 0.63 allows attackers to cause a denial of service (crash) via an image based fill in which the number of input channels is different from the number of output channels.

CVE-2007-2459 (2007-05-02)

Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files.

CPANSA-Imager-2014-01 (2014-01-03)

When drawing on an image with an alpha channel where the source minimum is greater than zero, Imager would read from beyond the end of a malloc() allocated buffer. In rare circumstances this could lead to some of the source image not being written to the target image, or possibly to a segmentation fault.

CVE-2024-53901 (2024-11-17)

"invalid next size" backtrace on use of trim on certain images

CVE-2006-0053 (2006-04-10)

Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.

CVE-2026-8669 (2026-05-15)

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.

CVE-2026-13705 (2026-07-06)

Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so a run with data_left / 2 < count <= data_left passes the guard yet consumes 2 * count bytes and reads past the end of the buffer. The 8-bit path is unaffected because there one pixel is one byte. Reading a crafted SGI image through Imager->read triggers the over-read before the parser rejects the malformed image, which can crash the process.

CVE-2026-14454 (2026-07-08)

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

Changes for version 0.47_01

  • set the locale to "C" properly when testing ft1.x error messages
  • don't destroy image before creating it in error handling in bmp.c
  • extra concept index entries
  • Imager::Draw - align_string()'s valign parameter was invalid in the synopsis
  • start of external Imager API access:
    • rename headers to avoid conflicts:
      • image.h to imager.h
      • imagei.h to imageri.h
      • datatypes.h to imdatatypes.h
      • config.h to imconfig.h (created by Makefile.PL)
    • moved all public types defined in imager.h to imdatatypes.h
    • supply the PM parameter to WriteMakefile(), to install headers under Imager/include, and the Imager typemap in Imager/typemap. We scan the MANIFEST for files to add to PM.
    • add "i_" prefix on some functions useful as public at the C level.
    • moved the typedefs that support the typemap from Imager.xs to imperl.h
    • set the global callbacks hook in the Imager.xs BOOT section
    • API cleanup:
      • define i_tags_set(), i_tags_setn() - we might not allow multiple values for a tag in the future
      • i_copy() now returns a new image instead of doing horrible inplace things to an existing image
      • provide actual functions for all of the macros we define in imager.h so we can put them in the global callbacks structure
    • define global functions structure (imexttypes.h) and initialize it (imext.c)
    • add API include header with macros to setup the define and initialize the local callbacks pointer, and macros to call the API functions.
    • build Imager::APIRef from C sources, including updating the sources to include documentation for each API function.
    • convert dyntest and mandelbrot dynfilts into XS modules (too easy)
    • simple Imager::CountColor example
  • support Inline::C :
    • typemap changes to accept Imager or Imager::ImgRaw objects as image parameters
    • define Imager output type for trivial cases of returning an i_img as a full Imager object
    • Inline WITH hook to filter Imager XS types into types Inline::C can accept, supply appropriate headers and initialization.
    • test script t/t82inline.t
  • try to use XSLoader instead of DynaLoader (but fallback if necessary)
  • paste() can now paste a subset of the source image.
  • paste() now has better tests
  • paste() should now be faster for larger pastes
  • added sample files missing from MANIFEST
  • added t/t92samples.t to check samples/README against MANIFEST
  • added inline_replace_color.pl to samples
  • constify the Imager API
  • document Imager::Filter::Mandelbrot
  • convert dynfilt/flines.c to Imager::Filter::Flines
  • minor changes for older perl/ExtUtils::MM
  • deal with freetype-config --cflags returning the directories in the wrong order (Freetype 2.1.4 and earlier) Thanks to David Wheeler for his help in tracking this down.
  • reword and provide an example for non-proportionally scaling an image. Wording from Simon Cozens.
  • error messages when writing TIFF images were always 'Could not write to buffer', more useful messages are now reported.
  • error messages when writing PNM images were always 'unable to write pnm image', more useful messages are now reported.
  • convert t/t103raw.t to Test::More
  • reading a raw image no longer exits on a short read or read error, and returns an appropriate error message in $im->errstr
  • write failures when writing a raw image now return a useful message in $im->errstr
  • added typemap type names to types in Imager::API.
  • make skip when Inline::C not available less verbose
  • convert t/t07iolayer.t to Test::More
  • handle the possibility of strerror() returning NULL.
  • supply C<imager> parameter to filters so we can register filters implemented in perl.
  • document register_filter() and add test for it
  • add example to SYNOPSIS of samples/inline_replace_color.pl
  • minor POD fix in Imager::Color::Table
  • eliminate many -Wall warnings
  • update README to match unbuggy giflib
  • document index parameter of Imager::Font->new()
  • change faxable output to use a more fax natural PHOTOMETRIC_MINISWHITE, since T.4 normally works that way, and MINISBLACK confuses some readers.
  • clean up scale() method for readability
  • make scale() fail if an invalid type is supplied (previously documented as undefined behaviour)
  • add error handling tests for scale()
  • smarter warning removal
  • handle effects of byte ordering when testing tiff error messages
  • scale() can now expect an Image::Math::Constrain object as a scaling constraint via the constrain parameter.
  • added tests for the various ways we can specify scaling size
  • documented scale()'s scalefactor parameter
  • sick of $opts{scalefactor} in scale(), give it a scalar to call it's own.
  • check $Config{ldflags} and $Config{ccflags} for places to search for headers and libraries. This deals with the way the fink build of perl puts -L/sw/lib in ldflags rather than using loclibpth
  • eliminate some of the duplication of -I and -L options in LIBS and INC
  • Makefile.PL now uses strict.
  • the search for freetype1.x headers is now smarter
  • add tests for scaleX()/scaleY()
  • expand documentation of scaleX()/scaleY()
  • rotate()s back parameter now accepts color names like other methods
  • convert t/t69rubthru.t to Test::More
  • minor clean up of rubthrough() method
  • error handling tests for rubthrough()
  • expand Imager::Transformations:
    • document parameters more explicitly
    • document return values
    • add examples
    • add AUTHOR, SEE ALSO, REVISION
  • eliminate sign warning from image.c
  • make TIFF detection stricter
  • more memory allocation integer overflow auditing
  • IM_DEBUG_MALLOC wasn't interacting well with the API
  • make win32.c const happy
  • make raw.c C89 compliant
  • added version/level to the API function table structure
  • fix/simplify META.yml generation - we now generate META.yml at Makefile.PL time, since trying to work with EU::MM to generate a custom META.yml was a waste.
  • bump to 0.47_01
    • For latest versions check the Imager-devel pages: http://imager.perl.org/

Documentation

recipes working with Imager
Draw primitives to images
Programmable transformation operations
working with image files
Entire Image Filtering Operations
Internal image representation information
using Imager with Inline::C.
Simple transformations of one image into another.
an introduction to Imager.
decribes the virtual image interface
documents the register virtual machine used by Imager::transform2().

Modules

demonstrates writing a simple function using Imager.
dim alternate lines to emulate a video display
Perl extension for Generating 24 bit Images
filter that renders the Mandelbrot set.
Imager's C API - introduction.
Imager's C API.
Color handling for Imager.
Rough floating point sample colour handling
built-in Imager color table
implements expression parsing and compilation for the expression evaluation engine used by Imager::transform2()
an assembler for producing code for the Imager register machine
functions handy in writing Imager extensions
general fill types
Font handling for Imager.
objects representing the bounding box of a string.
low-level functions for FreeType2 text output
low-level functions for Truetype fonts
low-level functions for Type1 fonts
uses Win32 GDI services for text output
simple wrapped text output
a class for building fountain fills suitable for use by the fountain filter.
simple wrapper for matrix construction
generated information about the register based VM
a library of register machine image transformations

Provides

in lib/Imager/Expr.pm
in lib/Imager/Expr.pm
in DynTest/DynTest.pm
in lib/Imager/Font/Image.pm