[
https://issues.apache.org/jira/browse/TIKA-3084?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Tim Allison updated TIKA-3084:
------------------------------
Description:
Our MP4 parser relies on googlecode's mp4parser. This hasn't been updated in a
while (March 2017). We can fairly seamlessly move to Sannies' fork, which was
last updated in Sept 2019.
I looked into this migration a while ago, and sannies had fixed several
problems in the older parser, but it had introduced some new catastrophic
vulnerabilities. Let's take a look now, and see where we are.
was:Our MP4 parser relies on googlecode's mp4parser. This hasn't been
updated in a while (March 2017). We can fairly seamlessly move to Sannies'
fork, which was last updated in Sept 2019.
> Migrate mp4 parsing to sannies' fork
> ------------------------------------
>
> Key: TIKA-3084
> URL: https://issues.apache.org/jira/browse/TIKA-3084
> Project: Tika
> Issue Type: Task
> Reporter: Tim Allison
> Priority: Major
>
> Our MP4 parser relies on googlecode's mp4parser. This hasn't been updated in
> a while (March 2017). We can fairly seamlessly move to Sannies' fork, which
> was last updated in Sept 2019.
> I looked into this migration a while ago, and sannies had fixed several
> problems in the older parser, but it had introduced some new catastrophic
> vulnerabilities. Let's take a look now, and see where we are.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)