CVE-2025-59728Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer. We recommend upgrading to version 8.0 or beyond.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-28: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 101-28
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Technical deep-dive now live. Analyzing CVE-2025-59728, the newly patched heap-based buffer overflow in FFmpeg for #Ubuntu. Read more: 👉 https://tinyurl.com/y4szwbw3 #Security https://t.co/dlzTKGlcnI

    Post summary

    The tweet announces that CVE‑2025‑59728, a heap-based buffer overflow in FFmpeg on Ubuntu, has been patched, and refers to a deep‑dive article for more details.

    0000071
    1.3K followersView on X

Explore more