Urs FleischandGitHub 0faf7291ca ASF: Verify if header size is valid
When saving a .wma file, ASF::File::save() does not validate the
header's headerSize field before using it in arithmetic. If its value
is below 30, an unsigned underflow and a subsequent integer overflow
cause FileStream::removeBlock() to compute a corrupted target offset,
resulting in an unbounded copy loop.

Credits for the discovery of this bug go to Ximena Molina Portilla,
Software Engineering student at Instituto Tecnológico de Costa Rica
(GitHub: @ximemolina).
2026-09-11 19:32:08 +02:00
2026-06-24 05:27:17 +02:00
2026-09-05 06:17:23 +02:00
2022-10-24 07:06:23 +02:00
2015-05-18 11:31:55 +02:00
2023-10-08 05:58:33 +02:00
2023-09-16 08:41:01 +02:00
2026-09-05 06:17:23 +02:00
2026-08-27 17:39:35 +02:00
2024-01-04 17:18:23 +01:00
2026-02-18 05:15:14 +01:00

TagLib

Build Status

TagLib Audio Metadata Library

https://taglib.org/

TagLib is a library for reading and editing the metadata of several popular audio formats. Currently, it supports various metadata containers such as ID3v1, ID3v2 and Vorbis comments for MP3, MP4, AAC, Ogg, Opus, FLAC, Speex, APE, MPC, WavPack, WAV, AIFF, TrueAudio, Matroska, WebM, ASF, WMA, DSF, DFF and tracker (MOD, XM, S3M, IT) files.

TagLib is distributed under the GNU Lesser General Public License (LGPL) and Mozilla Public License (MPL). Essentially that means that it may be used in proprietary applications, but if changes are made to TagLib they must be contributed back to the project. Please review the licenses if you are considering using TagLib in your project.

S
Description
No description provided
Readme
15 MiB
Languages
C++ 96.7%
CMake 2%
C 0.9%
Logos 0.4%