Skip to content

[GHSA-23f4-hfmq-94mj] Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec#7438

Open
carlosame wants to merge 1 commit intocarlosame/advisory-improvement-7438from
carlosame-GHSA-23f4-hfmq-94mj
Open

[GHSA-23f4-hfmq-94mj] Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec#7438
carlosame wants to merge 1 commit intocarlosame/advisory-improvement-7438from
carlosame-GHSA-23f4-hfmq-94mj

Conversation

@carlosame
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • CWEs
  • Severity

Comments
This vulnerability references a patch which is modifying correct code. In the pre-patch code, the bounds are checked by a call to a RandomAccessFile field, which implements the DataOutput interface. And the thing is writing to a file, not a buffer.

This "Buffer Overflow Vulnerability" is bogus: no buffer is involved and the RandomAccessFile works as intended.

@github-actions github-actions bot changed the base branch from main to carlosame/advisory-improvement-7438 April 19, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant