A vulnerability in the music-metadata library causes a synchronous infinite loop when parsing MP4 files with a sample description box entry size of 0, leading to a denial-of-service (DoS) attack. This issue is present on the master branch but not in the latest npm release (11.14.0) or earlier versions. The vulnerability is caused by the StsdAtom.get() function in lib/mp4/AtomToken.ts, which parses an MP4 [truncated]
A vulnerability in the music-metadata library allows for memory exhaustion via a specially crafted MP3 file with a truncated ID3v2 tag, causing a Denial of Service (DoS). The ID3v2 parser trusts the tag size field without validation, allocating a buffer of that size before reading, which can lead to memory exhaustion. This vulnerability affects all parsers that support ID3v2 tags, including MP3, FLAC, DSF [truncated]
A vulnerability in the music-metadata library allows for denial of service via memory exhaustion or process abort when parsing untrusted Matroska/WebM media. This issue arises from the EBML parser's failure to validate element lengths before using them for allocations. The vulnerability was demonstrated with specific inputs causing large allocations and a V8 fatal abort. The issue was reproduced on music- [truncated]
A vulnerability in the music-metadata library allows for an uncatchable process crash when parsing a crafted `.dsf` file. This issue arises from an unawaited call in the `DsfParser.parseChunks` method, which can lead to a negative argument being passed to `strtok3`, resulting in a `RangeError` and subsequently crashing the process. The vulnerability affects systems using the music-metadata library, partic [truncated]