Junglewise Threat Intelligence

CVE-2026-14454: TONYC Imager unsigned to signed conversion error in EXIF parsing

CVE-2026-14454 · Severity: info · CVSS 3.3 · Published 2026-07-08

Technologies: TONYC (Perl CPAN) Imager. Vendors: Tony Cook.

Executive brief

Imager, a Perl library used for image processing and manipulation, contains a flaw in how it handles metadata (EXIF data) in image files. An attacker can provide a specially crafted image that, when processed by the library, causes the application to crash by attempting to allocate an impossible amount of memory. This results in a denial-of-service, potentially stopping web servers or background tasks that process user-uploaded images.

Technical details

A signedness error (CWE-196) exists in the EXIF parsing logic of Imager (specifically in `imexif.c`). The library treats unsigned EXIF Image File Directory (IFD) entry counts as signed integers. When a large value is encountered, it is interpreted as a negative number, which subsequently leads to an excessive memory allocation request (CWE-789) near the size of the address space. This allocation failure triggers a process crash. An attacker can exploit this by providing a crafted image with malicious EXIF metadata to cause a Denial of Service (DoS). The issue is fixed in version 1.033 by updating the relevant types to `unsigned` and `size_t`.

Affected products

  • TONYC (Perl CPAN) Imager before 1.033

Timeline

  • 2026-07-04: patched: Fix committed to repository
  • 2026-07-08: disclosed: CVE published

References

Related threats