Impact
The MP4 parser in music‑metadata accepts a 64‑bit extended atom size supplied by the file header, converts it to a JavaScript Number, and uses that value as the length for subsequent read operations before verifying that the atom fits within its parent or the remaining input. A maliciously crafted MP4 file can therefore convey an oversized length that leads the parser to attempt an extremely large allocation or to crash the process during payload parsing for atoms such as mvhd, stsd, stsz, or date. The resulting memory exhaustion or failure causes the host application to become unresponsive, effectively denying service. This vulnerability is specific to the parsing of MP4‑family files and exploits an improper bounds check identified as CWE‑789.
Affected Systems
The affected product is the Borewit music‑metadata library, with all releases prior to version 11.16.0 vulnerable. Applications that embed or import this library to process user‑supplied MP4 or related media files are at risk, regardless of the hosting environment. The issue does not affect native media players that do not use music‑metadata.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity, and the EPSS score is not available, meaning no current data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker providing a crafted MP4 file to the application, either through local file upload or remote media ingestion, which triggers the excessive memory allocation and leads to denial of service. No authentication or elevated privileges are required, allowing remote unauthenticated exploitation if the application exposes a file processing endpoint.
OpenCVE Enrichment