[
https://issues.apache.org/jira/browse/TIKA-3084?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17080984#comment-17080984
]
Tim Allison commented on TIKA-3084:
-----------------------------------
I forked sannies parser for now: https://github.com/tballison/mp4parser and
released it to maven central.
> Migrate mp4 parsing to sannies' fork
> ------------------------------------
>
> Key: TIKA-3084
> URL: https://issues.apache.org/jira/browse/TIKA-3084
> Project: Tika
> Issue Type: Task
> Reporter: Tim Allison
> Priority: Major
>
> Our MP4 parser relies on googlecode's mp4parser. This hasn't been updated in
> a while (March 2017). We can fairly seamlessly move to Sannies' fork, which
> was last updated in Sept 2019.
> I looked into this migration a while ago, and sannies had fixed several
> problems in the older parser, but it had introduced some new catastrophic
> vulnerabilities. Let's take a look now, and see where we are.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)