MGASA-2026-0284

Source
https://advisories.mageia.org/MGASA-2026-0284.html
Import Source
https://advisories.mageia.org/MGASA-2026-0284.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0284
Upstream
Published
2026-07-20T19:06:32Z
Modified
2026-07-20T19:15:05.272142173Z
Summary
Updated perl-Imager package fixes security vulnerabilities
Details

The updated package fixes security vulnerabilities: The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. (CVE-2024-53901) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in readrgb16rle. (CVE-2026-13705) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in ireadjpeg_wiol. (CVE-2026-13708) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. (CVE-2026-14454)

References
Credits

Affected packages

Mageia:10 / perl-Imager

Package

Name
perl-Imager
Purl
pkg:rpm/mageia/perl-Imager?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.33.0-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0284.json"

Mageia:9 / perl-Imager

Package

Name
perl-Imager
Purl
pkg:rpm/mageia/perl-Imager?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.19.0-2.2.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0284.json"