Security Advisories (1)
CVE-2022-23935 (2022-01-25)

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

NAME

Image::ExifTool::QuickTime - Read QuickTime and MP4 meta information

SYNOPSIS

This module is used by Image::ExifTool

DESCRIPTION

This module contains routines required by Image::ExifTool to extract information from QuickTime and MP4 video, and M4A audio files.

AUTHOR

Copyright 2003-2008, Phil Harvey (phil at owl.phy.queensu.ca)

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

REFERENCES

http://developer.apple.com/documentation/QuickTime/
http://search.cpan.org/dist/MP4-Info-1.04/
http://www.geocities.com/xhelmboyx/quicktime/formats/mp4-layout.txt
http://wiki.multimedia.cx/index.php?title=Apple_QuickTime

SEE ALSO

"QuickTime Tags" in Image::ExifTool::TagNames, Image::ExifTool(3pm)