Logo
vulnerabilityCVE-2025-59730
Name
CVE-2025-59730
Source
NVD ( link)Debian ( link)
Description
When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution. This codec can encode the frame contents using a run-length encoding algorithm. There are no checks that the decoded frame fits in the allocated buffer, leading to a heap-buffer-overflow. process_frame_obj initializes the buffers based on the frame resolution: We recommend upgrading to version 8.0 or beyond.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
ffmpeg
Not Affected

Vulnerability Ratings#


5.7
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
kirkstone
5.0.3
Not Affected
yocto
scarthgap
6.1.4
Not Affected