VDB

GCVE-110-MAGEIA-2026-284

GCVE-110-MAGEIA-2026-284
Advisory Published
Vulnetix · Advisory published July 20, 2026
The updated package fixes security vulnerabilities: The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. (CVE-2024-53901) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. (CVE-2026-13705) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. (CVE-2026-13708) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. (CVE-2026-14454)

Affected Products

VendorProductVersionsPlatforms
Mageiaperl-Imager0 (affected), 1.19.0-2.2.mga9 (unaffected)
Mageiaperl-Imager0 (affected), 1.33.0-1.mga10 (unaffected)

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›