Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23f4-hfmq-94mj

Опубликовано: 27 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec

Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java.

This issue affects all versions of quick-media. A patch is available: 3970e96

Пакеты

Наименование

com.github.liuyueyi.media:batik-codec-fix

maven
Затронутые версииВерсия исправления

<= 3.0.0

Отсутствует

EPSS

Процентиль: 6%
0.00023
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-120
CWE-190

Связанные уязвимости

nvd
8 дней назад

Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java. This issue affects quick-media: before v1.0.

EPSS

Процентиль: 6%
0.00023
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-120
CWE-190