PT-2025-40876 · Sanm · Sanm
Published
2025-07-28
·
Updated
2025-11-15
·
CVE-2025-59730
CVSS v4.0
5.7
Medium
| Vector | AV:A/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Versions prior to 8.0
Description
A heap-buffer-overflow can occur when decoding a frame for a SANM file (ANIM v0 variant). Frames encoded with codec 48 can specify their resolution (width x height), and a buffer is allocated based on this resolution. The codec uses a run-length encoding algorithm, but there are no checks to ensure the decoded frame fits within the allocated buffer. The
process frame obj function initializes the buffers based on the frame resolution.Recommendations
Upgrade to version 8.0 or beyond.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sanm