Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries
Summary
| CVE | CVE-2022-4988 |
|---|---|
| State | PUBLISHED |
| Assigner | CPANSec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-11 20:19:35 UTC |
| Updated | 2026-05-12 16:48:58 UTC |
| Description | Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have known vulnerabilities. |
Risk And Classification
EPSS: 0.000240000 probability, percentile 0.070360000 (date 2026-05-12)
Problem Types: CWE-1395 CWE-1395 Dependency on Vulnerable Third-Party Component
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | KMX | AlienFreeImage | affected 1.001 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/kmx/alien-freeimage/issues/5 | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| nvd.nist.gov/vuln/detail/CVE-2015-0852 | 9b29abf9-4ab0-4765-b253-1875cd9b441e | nvd.nist.gov | |
| metacpan.org/release/KMX/Alien-FreeImage-1.001/source/src/Source | 9b29abf9-4ab0-4765-b253-1875cd9b441e | metacpan.org | |
| github.com/kmx/alien-freeimage/issues/4 | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| freeimage.sourceforge.io | 9b29abf9-4ab0-4765-b253-1875cd9b441e | freeimage.sourceforge.io | |
| nvd.nist.gov/vuln/detail/CVE-2025-65803 | 9b29abf9-4ab0-4765-b253-1875cd9b441e | nvd.nist.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2017-07-11T00:00:00.000Z | Alien::FreeImage released with FreeImage 3.17.0 |
| CNA | 2022-06-29T00:00:00.000Z | Issues added to git repository regarding security vulnerabilities |
| CNA | 2022-06-29T00:00:00.000Z | Several issues added to CPANSA::DB |
| CNA | 2026-03-27T00:00:00.000Z | Issues logged with CPANSec |
Workarounds
CNA: The latest version of the FreeImage library is 3.18.0 from 2018, which also appears to have serious vulnerabilities. Users are advised to use alternatives.
There are currently no legacy QID mappings associated with this CVE.