VYPR
High severity7.3NVD Advisory· Published May 11, 2026· Updated May 13, 2026

CVE-2022-4988

CVE-2022-4988

Description

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries.

Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have known vulnerabilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Alien::FreeImage Perl module bundles outdated FreeImage 3.17.0 with known vulnerabilities, exposing applications to multiple security risks.

Vulnerability

Overview

Alien::FreeImage is a Perl module that bundles the FreeImage library (version 3.17.0, released in 2017) along with other embedded image libraries. This version of FreeImage contains multiple known security vulnerabilities, including CVE-2015-0852 and CVE-2025-65803 [1][2]. Additionally, the module embeds a version of zlib that has its own security issues [4]. The root cause is the use of outdated, unpatched dependencies.

Exploitation

Conditions

Applications that use Alien::FreeImage to process image files are vulnerable. An attacker can exploit these flaws by supplying a specially crafted image file (e.g., TIFF, PNG, or other formats handled by FreeImage). No authentication is required if the application accepts user-provided images. The attack vector can be local or remote, depending on how the application ingests images.

Impact

Successful exploitation could allow an attacker to execute arbitrary code, cause a denial of service, or leak sensitive information. For instance, CVE-2015-0852 is a heap-based buffer overflow in FreeImage's TIFF parsing that can lead to code execution [1]. CVE-2025-65803 is another vulnerability in the same library [2]. The embedded zlib issues may further expand the attack surface [4].

Mitigation

As of the CVE publication, Alien::FreeImage versions up to and including 1.001 are affected. No official patch has been released for the Perl module. Users should consider upgrading to a newer version of Alien::FreeImage if available, or avoid using the module altogether. The FreeImage project has released newer versions, but the module has not been updated to incorporate them [3].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.