CVE-2026-14454
imager: Unsigned to Signed Conversion Error (CVE-2026-14454)
Affected
- tonycoz/imager
lt *..1.033
Description
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.033fixed from 1.033Metrics
Show all metrics
Weakness classes (CWE)
CWE-196Variant
Unsigned to Signed Conversion Error
The product uses an unsigned primitive and performs a cast to a signed primitive, which can produce an unexpected value if the value of the unsigned primitive can not be represented using a signed primitive.
cwe.mitre.org →CWE-789Variant
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
cwe.mitre.org →