Comments (4)
poc:
https://gitee.com/hac425/fuzz_data/blob/master/mp4v2_vtable_poc.mp4
from mp4v2.
This was assigned CVE-2018-14446.
from mp4v2.
Thank you for reporting this! We are looking into it.
from mp4v2.
It has come to our attention that there are a number of CVE's assigned to mp4v2. All of these reference a CPE of a:techsmith:mp4v2. I believe this was an educated guess by NIST as to the owner of the mp4v2 code. After all, if you search for mp4v2 this repository shows up in the results first.
@jinyu00 was the only one to have logged an issue against our fork specifically.
I want to make it clear to the community that this is repository is a fork of https://code.google.com/archive/p/mp4v2/. We have made some changes on top of it for our own purposes and they remain open source.
Our fork here is certainly vulnerable to these issues which we intend to resolve, but I'm sure most binary distributions of this library are not built off of this fork and will need to implement their own fixes and version appropriately. We will be editing the readme to clarify the nature of this fork going forward.
from mp4v2.
Related Issues (20)
- Project version number incosistency
- Chapter titles can be encoded in UTF-16
- mp4file.exe destroys .mpa/mp4 files.
- MP4TagsSetTVSeason with season set to null doesn't delete tvsn atom
- files lost or files size was 0Kb HOT 1
- Set duration on the file level
- Unable to determine total duration from chapter.txt
- Can mp4v2 encapsulate h265 HOT 8
- Question about chapter data
- Apple Silicon
- Version 4.1.4/4.1.5 breaks applications written in C (such as cmus) HOT 7
- Build failures under GCC 10 HOT 7
- Documentation files do not exist
- ReadProperties: atom 'avcC' is too small; overrun at property: configurationVersion (src/mp4atom.cpp,399) HOT 2
- Doesn't read chapters defined in moov.udata.chpl HOT 3
- Cannot compile
- About MP4 file power failure problem
- Heap-buffer-overflow src/mp4property.cpp:338:17 in mp4v2::impl::MP4StringProperty::~MP4StringProperty() HOT 1
- Can mp4v2 be used to edit audio files in m4a format?
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from mp4v2.