漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
Vulnerability Description
Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle.
read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so a run with data_left / 2 < count <= data_left passes the guard yet consumes 2 * count bytes and reads past the end of the buffer. The 8-bit path is unaffected because there one pixel is one byte.
Reading a crafted SGI image through Imager->read triggers the over-read before the parser rejects the malformed image, which can crash the process.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
TONYC Imager 缓冲区错误漏洞
Vulnerability Description
tonyc Imager是tonyc的嵌入式服务器。 TONYC Imager 1.032之前版本存在缓冲区错误漏洞,该漏洞源于在Imager::File::SGI读取器中,16位RLE文字运行处理时存在堆越界读取,可能导致读取特制SGI图像时触发越界读取并导致进程崩溃。
CVSS Information
N/A
Vulnerability Type
N/A