Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
Vulnerability Description
Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol.
i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without freeing it. Only the final payload is later turned into a Perl scalar and freed, so a JPEG with N such markers leaks the first N-1 payloads on every read.
In a long-lived process, such as an upload or thumbnailing service, repeated reads accumulate these leaks and exhaust available memory, a denial of service.
The same handler ships bundled in the Imager distribution, where versions before 1.032 are affected and the fix ships in 1.032.
CVSS Information
N/A
Vulnerability Type
在移除最后引用时对内存的释放不恰当(内存泄露)
Vulnerability Title
TONYC Imager::File::JPEG 资源管理错误漏洞
Vulnerability Description
TONYC Imager::File::JPEG是TONYC个人开发者的一款JPEG图像处理模块。 TONYC Imager::File::JPEG 1.003之前版本存在资源管理错误漏洞,该漏洞源于在i_readjpeg_wiol中读取带有重复APP13标记的JPEG文件时,对每个APP13标记分配新缓冲区后未释放先前指针,造成堆内存泄漏,在长期运行过程中累积泄漏并耗尽可用内存,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A