mirror of
https://github.com/taglib/taglib.git
synced 2026-08-27 12:47:01 -04:00
0a3deeac75618c4820f04aff270fa62a27c48682
A malformed QuickTime chapter track can set stsz's default sample size to a value larger than the available sample data. MP4::File::qtChapters() passes that value through QtChapterList::read() to readTextSample(), allowing a small file to cause gigabytes of allocations and terminate the application. Check each resolved sample against the file end and the next sample offset before reading it. Samples that do not fit are rejected without allocating the attacker-controlled size.
TagLib
TagLib Audio Metadata Library
TagLib is a library for reading and editing the metadata of several popular audio formats. Currently, it supports various metadata containers such as ID3v1, ID3v2 and Vorbis comments for MP3, MP4, AAC, Ogg, Opus, FLAC, Speex, APE, MPC, WavPack, WAV, AIFF, TrueAudio, Matroska, WebM, ASF, WMA, DSF, DFF and tracker (MOD, XM, S3M, IT) files.
TagLib is distributed under the GNU Lesser General Public License (LGPL) and Mozilla Public License (MPL). Essentially that means that it may be used in proprietary applications, but if changes are made to TagLib they must be contributed back to the project. Please review the licenses if you are considering using TagLib in your project.
Languages
C++
96.7%
CMake
2%
C
0.9%
Logos
0.4%