Acts1631andGitHub 0a3deeac75 Reject QuickTime chapter samples outside their data bounds (#1427)
A malformed QuickTime chapter track can set stsz's default sample size to a
value larger than the available sample data. MP4::File::qtChapters() passes
that value through QtChapterList::read() to readTextSample(), allowing a
small file to cause gigabytes of allocations and terminate the application.

Check each resolved sample against the file end and the next sample offset
before reading it. Samples that do not fit are rejected without allocating
the attacker-controlled size.
2026-08-21 05:43:54 +02:00
2026-06-24 05:27:17 +02:00
2026-07-19 19:58:28 +02:00
2022-10-24 07:06:23 +02:00
2026-08-14 06:47:05 +02:00
2015-05-18 11:31:55 +02:00
2023-10-08 05:58:33 +02:00
2023-09-16 08:41:01 +02:00
2026-07-19 19:58:28 +02:00
2026-07-12 20:16:12 +02:00
2024-01-04 17:18:23 +01:00
2026-02-18 05:15:14 +01:00

TagLib

Build Status

TagLib Audio Metadata Library

https://taglib.org/

TagLib is a library for reading and editing the metadata of several popular audio formats. Currently, it supports various metadata containers such as ID3v1, ID3v2 and Vorbis comments for MP3, MP4, AAC, Ogg, Opus, FLAC, Speex, APE, MPC, WavPack, WAV, AIFF, TrueAudio, Matroska, WebM, ASF, WMA, DSF, DFF and tracker (MOD, XM, S3M, IT) files.

TagLib is distributed under the GNU Lesser General Public License (LGPL) and Mozilla Public License (MPL). Essentially that means that it may be used in proprietary applications, but if changes are made to TagLib they must be contributed back to the project. Please review the licenses if you are considering using TagLib in your project.

S
Description
No description provided
Readme
15 MiB
Languages
C++ 96.7%
CMake 2%
C 0.9%
Logos 0.4%