mirror of
https://github.com/taglib/taglib.git
synced 2026-08-27 12:47:01 -04:00
d391029695adfa9a7ecbd7dc35933eb0d509fbd3
A QuickTime chapter track can provide large stco and stsc tables. QtChapterList::resolveSampleOffsets() currently walks every stsc entry for every chunk, so a file with N entries can force O(N²) work during MP4::File::qtChapters(). A 3.2 MB file with 200,000 entries took about 20 seconds in the release build. Keep a cursor into stscEntries and advance it as chunk numbers increase. This resolves the same ordered table in linear time while avoiding attacker-controlled repeated scans.
TagLib
TagLib Audio Metadata Library
TagLib is a library for reading and editing the metadata of several popular audio formats. Currently, it supports various metadata containers such as ID3v1, ID3v2 and Vorbis comments for MP3, MP4, AAC, Ogg, Opus, FLAC, Speex, APE, MPC, WavPack, WAV, AIFF, TrueAudio, Matroska, WebM, ASF, WMA, DSF, DFF and tracker (MOD, XM, S3M, IT) files.
TagLib is distributed under the GNU Lesser General Public License (LGPL) and Mozilla Public License (MPL). Essentially that means that it may be used in proprietary applications, but if changes are made to TagLib they must be contributed back to the project. Please review the licenses if you are considering using TagLib in your project.
Languages
C++
96.7%
CMake
2%
C
0.9%
Logos
0.4%