PT-2025-40876 · Sanm · Sanm

CVE-2025-59730

·

Published

2025-07-28

·

Updated

2025-11-15

CVSS v4.0

5.7

Medium

VectorAV:A/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Versions prior to 8.0
Description A heap-buffer-overflow can occur when decoding a frame for a SANM file (ANIM v0 variant). Frames encoded with codec 48 can specify their resolution (width x height), and a buffer is allocated based on this resolution. The codec uses a run-length encoding algorithm, but there are no checks to ensure the decoded frame fits within the allocated buffer. The process frame obj function initializes the buffers based on the frame resolution.
Recommendations Upgrade to version 8.0 or beyond.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12717
CVE-2025-59730

Affected Products

Sanm