Security Advisories (3)
CVE-2026-8669 (2026-05-15)

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.

CVE-2026-13705 (2026-07-06)

Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so a run with data_left / 2 < count <= data_left passes the guard yet consumes 2 * count bytes and reads past the end of the buffer. The 8-bit path is unaffected because there one pixel is one byte. Reading a crafted SGI image through Imager->read triggers the over-read before the parser rejects the malformed image, which can crash the process.

CVE-2026-14454 (2026-07-08)

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

NAME

Imager::Font::Type1 - low-level functions for Type1 fonts

DESCRIPTION

Imager::Font::T1 is deprecated.

T1Lib is unmaintained and has serious bugs when built on 64-bit systems. Freetype 2 has Type 1 font support and is supported by Imager via Imager::Font::FT2.

Imager::Font creates a Imager::Font::Type1 object when asked to create a font object based on a .pfb file.

See Imager::Font to see how to use this type.

This class provides low-level functions that require the caller to perform data validation

By default Imager no longer creates the t1lib.log log file. You can re-enable that by calling Imager::init() with the t1log option:

Imager::init(t1log=>1);

This must be called before creating any fonts.

Currently specific to Imager::Font::Type1, you can use the following flags when drawing text or calculating a bounding box:

  • underline - Draw the text with an underline.

  • overline - Draw the text with an overline.

  • strikethrough - Draw the text with a strikethrough.

Obviously, if you're calculating the bounding box the size of the line is included in the box, and the line isn't drawn :)

Anti-aliasing

T1Lib supports multiple levels of anti-aliasing, by default, if you request anti-aliased output, Imager::Font::T1 will use the maximum level.

You can override this with the set_t1_aa() method:

set_aa_level()

Usage:

$font->set_aa_level(1);
Imager::Font::T1->set_aa_level(2);

Sets the T1Lib anti-aliasing level either for the specified font, or for new font objects.

The only parameter must be 1 or 2.

Returns true on success.

AUTHOR

Addi, Tony