CVE Explorer
CVE-2026-14454
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.
An attacker could craft an image with EXIF data that terminates a worker process.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-196","description":"CWE-196 Unsigned to Signed Conversion Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-789","description":"CWE-789 Memory Allocation with Excessive Size Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Imager","product":"Imager","programFiles":["imexif.c"],"programRoutines":[{"name":"tiff_load_ifd"}],"repo":"https://github.com/tonycoz/imager","vendor":"TONYC","versions":[{"lessThan":"1.033","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-196","description":"CWE-196 Unsigned to Signed Conversion Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-789","description":"CWE-789 Memory Allocation with Excessive Size Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/07/08/6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/references/1
{"tags":["release-notes"],"url":"https://metacpan.org/release/TONYC/Imager-1.033/changes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bec05e74c83f5ef67706194d4756928e61a40f035cd688ee0bdfccadd6ac0d7e · sha256:334b9dc0205c0c31… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.