{"id":"DEBIAN-CVE-2025-59730","details":"When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it.  Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution.  This codec can encode the frame contents using a run-length encoding algorithm. There are no checks that the decoded frame fits in the allocated buffer, leading to a heap-buffer-overflow.  process_frame_obj initializes the buffers based on the frame resolution:    We recommend upgrading to version 8.0 or beyond.","modified":"2025-11-04T14:23:45.852191Z","published":"2025-10-06T08:15:34Z","withdrawn":"2025-11-04T14:23:45.852191Z","upstream":["CVE-2025-59730"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-59730"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"Debian:11","purl":"pkg:deb/debian/ffmpeg?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7:4.3.2-0+deb11u2","7:4.3.2-1","7:4.3.2-2","7:4.3.3-0+deb11u1","7:4.3.4-0+deb11u1","7:4.3.5-0+deb11u1","7:4.3.6-0+deb11u1","7:4.3.7-0+deb11u1","7:4.3.8-0+deb11u1","7:4.3.8-0+deb11u2","7:4.3.8-0+deb11u3","7:4.3.9-0+deb11u1","7:4.4-1","7:4.4-2","7:4.4-3","7:4.4-4","7:4.4-5","7:4.4-6","7:4.4.1-1","7:4.4.1-2","7:4.4.1-2+ports","7:4.4.1-3","7:4.4.2-1","7:5.0-1","7:5.0-2","7:5.0-3","7:5.0.1-1","7:5.0.1-2","7:5.0.1-3","7:5.1-1","7:5.1-2","7:5.1-2.1","7:5.1-3","7:5.1.1-1","7:5.1.1-2","7:5.1.1-2+m68k","7:5.1.2-1","7:5.1.2-2","7:5.1.2-3","7:5.1.3-1","7:5.1.3-2","7:6.0-1","7:6.0-2","7:6.0-3","7:6.0-4","7:6.0-5","7:6.0-6","7:6.0-7","7:6.0-8","7:6.0-9","7:6.1-1","7:6.1-2","7:6.1-3","7:6.1-4","7:6.1-5","7:6.1.1-1","7:6.1.1-2","7:6.1.1-3","7:6.1.1-4","7:6.1.1-5","7:7.0-1","7:7.0.1-1","7:7.0.1-2","7:7.0.1-3","7:7.0.1-4","7:7.0.1-5","7:7.0.2-1","7:7.0.2-2","7:7.0.2-3","7:7.1-1","7:7.1-2","7:7.1-3","7:7.1-4","7:7.1.1-1","7:7.1.2-1","7:8.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-59730.json"}},{"package":{"name":"ffmpeg","ecosystem":"Debian:12","purl":"pkg:deb/debian/ffmpeg?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7:5.1.3-1","7:5.1.3-2","7:5.1.4-0+deb12u1","7:5.1.5-0+deb12u1","7:5.1.6-0+deb12u1","7:5.1.7-0+deb12u1","7:6.0-1","7:6.0-2","7:6.0-3","7:6.0-4","7:6.0-5","7:6.0-6","7:6.0-7","7:6.0-8","7:6.0-9","7:6.1-1","7:6.1-2","7:6.1-3","7:6.1-4","7:6.1-5","7:6.1.1-1","7:6.1.1-2","7:6.1.1-3","7:6.1.1-4","7:6.1.1-5","7:7.0-1","7:7.0.1-1","7:7.0.1-2","7:7.0.1-3","7:7.0.1-4","7:7.0.1-5","7:7.0.2-1","7:7.0.2-2","7:7.0.2-3","7:7.1-1","7:7.1-2","7:7.1-3","7:7.1-4","7:7.1.1-1","7:7.1.2-1","7:8.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-59730.json"}},{"package":{"name":"ffmpeg","ecosystem":"Debian:13","purl":"pkg:deb/debian/ffmpeg?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7:7.1.1-1","7:7.1.2-0+deb13u1","7:7.1.2-1","7:8.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-59730.json"}},{"package":{"name":"ffmpeg","ecosystem":"Debian:14","purl":"pkg:deb/debian/ffmpeg?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7:7.1.1-1","7:7.1.2-1","7:8.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-59730.json"}}],"schema_version":"1.7.3"}