CVE-2024-53901

The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tonyc:imager:*:*:*:*:*:perl:*:*

History

26 Nov 2024, 19:52

Type Values Removed Values Added
Summary
  • (es) El paquete Imager anterior a 1.025 para Perl tiene un desbordamiento de búfer basado en montón que provoca una denegación de servicio, o posiblemente otro impacto no especificado, cuando se llama al método trim() en una imagen de entrada manipulado.
CPE cpe:2.3:a:tonyc:imager:*:*:*:*:*:perl:*:*
CWE CWE-787
First Time Tonyc imager
Tonyc
References () https://github.com/briandfoy/cpan-security-advisory/issues/167 - () https://github.com/briandfoy/cpan-security-advisory/issues/167 - Issue Tracking, Patch
References () https://github.com/briandfoy/cpan-security-advisory/issues/171 - () https://github.com/briandfoy/cpan-security-advisory/issues/171 - Issue Tracking
References () https://github.com/tonycoz/imager/issues/534 - () https://github.com/tonycoz/imager/issues/534 - Exploit, Issue Tracking
References () https://metacpan.org/release/TONYC/Imager-1.025/changes - () https://metacpan.org/release/TONYC/Imager-1.025/changes - Release Notes

24 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-24 17:15

Updated : 2024-11-26 19:52


NVD link : CVE-2024-53901

Mitre link : CVE-2024-53901

CVE.ORG link : CVE-2024-53901


JSON object : View

Products Affected

tonyc

  • imager
CWE
CWE-787

Out-of-bounds Write

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')