Security Advisories (1)
CVE-2026-19082 (2026-08-07)

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via im_decode_exif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager. Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif_* tag holding adjacent heap bytes instead of an empty string.

NAME

Imager::Inline - using Imager with Inline::C.

SYNOPSIS

use Inline with => 'Imager';
use Inline C => <<'EOS';
Imager some_func(Imager::Color c, Imager::Fill f) {
  Imager img = i_img_8_new(200, 200, 3);
  /* fill with color */
  i_box_filled(img, 0, 0, 199, 199, c);
  /* inner area with fill */
  i_box_cfill(img, 50, 50, 149, 149, f);

  return img;
}
EOS

DESCRIPTION

Imager hooks into Inline's with syntax to make it easier to write Inline::C code that works with Imager, you can call Imager functions without having to include headers or perform initialization.

Imager's Inline with support does the following:

  • add the installed Imager include directory to INC

  • add the Imager typemap to TYPEMAPS

  • include the headers needed by Imager C extension modules.

  • declare and initialize the Imager API function table pointer

  • filter the supplied code to replace Imager's class names with those that Inline::C can handle.

LIMITATIONS

The filtering mechanism is global, it will replace the class names even inside string constants. If you need a string matching the name of one of Imager's classes, like "Imager::Color" you will need to split it into 2 to use C's string pasting mechanism, for example: "Imager:" ":Color".

AUTHOR

Tony Cook <tonyc@cpan.org>

REVISION

$Revision$

SEE ALSO

Imager, Imager::ExtUtils, Imager::API, Imager::APIRef, samples/inline_replace_color.pl