mirror of
https://github.com/taglib/taglib.git
synced 2026-09-23 01:46:59 -04:00
0faf7291ca654760b69599efdc3b21e6fbb28afa
When saving a .wma file, ASF::File::save() does not validate the header's headerSize field before using it in arithmetic. If its value is below 30, an unsigned underflow and a subsequent integer overflow cause FileStream::removeBlock() to compute a corrupted target offset, resulting in an unbounded copy loop. Credits for the discovery of this bug go to Ximena Molina Portilla, Software Engineering student at Instituto Tecnológico de Costa Rica (GitHub: @ximemolina).
TagLib
TagLib Audio Metadata Library
TagLib is a library for reading and editing the metadata of several popular audio formats. Currently, it supports various metadata containers such as ID3v1, ID3v2 and Vorbis comments for MP3, MP4, AAC, Ogg, Opus, FLAC, Speex, APE, MPC, WavPack, WAV, AIFF, TrueAudio, Matroska, WebM, ASF, WMA, DSF, DFF and tracker (MOD, XM, S3M, IT) files.
TagLib is distributed under the GNU Lesser General Public License (LGPL) and Mozilla Public License (MPL). Essentially that means that it may be used in proprietary applications, but if changes are made to TagLib they must be contributed back to the project. Please review the licenses if you are considering using TagLib in your project.
Languages
C++
96.7%
CMake
2%
C
0.9%
Logos
0.4%