PT-2025-40876 · Sanm · Sanm

Published

2025-07-28

·

Updated

2025-11-15

·

CVE-2025-59730

CVSS v4.0

5.7

Medium

VectorAV:A/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Versions prior to 8.0
Description A heap-buffer-overflow can occur when decoding a frame for a SANM file (ANIM v0 variant). Frames encoded with codec 48 can specify their resolution (width x height), and a buffer is allocated based on this resolution. The codec uses a run-length encoding algorithm, but there are no checks to ensure the decoded frame fits within the allocated buffer. The process frame obj function initializes the buffers based on the frame resolution.
Recommendations Upgrade to version 8.0 or beyond.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-12717
CVE-2025-59730

Affected Products

Sanm