Security Advisories (2)
CVE-2024-53901 (2024-11-17)

"invalid next size" backtrace on use of trim on certain images

CVE-2026-8669 (2026-05-15)

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.

NAME

Imager::Inline - using Imager with Inline::C.

SYNOPSIS

use Inline with => 'Imager';
use Inline C => <<'EOS';
Imager some_func(Imager::Color c, Imager::Fill f) {
  Imager img = i_img_8_new(200, 200, 3);
  /* fill with color */
  i_box_filled(img, 0, 0, 199, 199, c);
  /* inner area with fill */
  i_box_cfill(img, 50, 50, 149, 149, f);

  return img;
}
EOS

DESCRIPTION

Imager hooks into Inline's with syntax to make it easier to write Inline::C code that works with Imager, you can call Imager functions without having to include headers or perform initialization.

Imager's Inline with support does the following:

  • add the installed Imager include directory to INC

  • add the Imager typemap to TYPEMAPS

  • include the headers needed by Imager C extension modules.

  • declare and initialize the Imager API function table pointer

  • filter the supplied code to replace Imager's class names with those that Inline::C can handle.

LIMITATIONS

The filtering mechanism is global, it will replace the class names even inside string constants. If you need a string matching the name of one of Imager's classes, like "Imager::Color" you will need to split it into 2 to use C's string pasting mechanism, for example: "Imager:" ":Color".

AUTHOR

Tony Cook <tonyc@cpan.org>

REVISION

$Revision$

SEE ALSO

Imager, Imager::ExtUtils, Imager::API, Imager::APIRef, samples/inline_replace_color.pl