{"id":"CVE-2025-58447","summary":"rAthena has heap-based buffer overflow in login server","details":"rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the login server, remote attacker to overwrite adjacent session fields by sending a crafted `CA_SSO_LOGIN_REQ` with an oversized token length. This leads to immediate denial of service (crash) and it is possible to achieve remote code execution via heap corruption. Commit 2f5248b fixes the issue.","aliases":["GHSA-4p33-6xqr-cm6x"],"modified":"2026-08-12T15:17:02.502417Z","published":"2025-09-09T22:11:03.376Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58447.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"2f5248b"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58447.json"},{"type":"ADVISORY","url":"https://github.com/rathena/rathena/security/advisories/GHSA-4p33-6xqr-cm6x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58447"},{"type":"FIX","url":"https://github.com/rathena/rathena/commit/2f5248b9cd9a8c6b42422ddecfc4cc2cd0e69e4b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rathena/rathena","events":[{"introduced":"0"},{"fixed":"2f5248b9cd9a8c6b42422ddecfc4cc2cd0e69e4b"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures":[{"digest":{"line_hashes":["301469459589491380462600020940278387632","100118674506182665544821448511249522469","316118351100221714783085151324964126564","291141367328178332968123274634032556917"],"threshold":0.9},"id":"CVE-2025-58447-b85679ff","signature_type":"Line","signature_version":"v1","source":"https://github.com/rathena/rathena/commit/2f5248b9cd9a8c6b42422ddecfc4cc2cd0e69e4b","target":{"file":"src/login/loginclif.cpp"},"deprecated":false},{"id":"CVE-2025-58447-f444da85","signature_type":"Function","signature_version":"v1","source":"https://github.com/rathena/rathena/commit/2f5248b9cd9a8c6b42422ddecfc4cc2cd0e69e4b","target":{"file":"src/login/loginclif.cpp","function":"logclif_parse_reqauth_sso"},"deprecated":false,"digest":{"function_hash":"121707411016889437678516243908855743161","length":796}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58447.json","vanir_signatures_modified":"2026-08-12T15:17:02Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}