PT-2024-19802 · Biosig+1 · Libbiosig+1

Lilith >_>

·

Published

2024-02-09

·

Updated

2025-12-16

·

CVE-2024-23313

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Biosig Project libbiosig version 2.5.0 The Biosig Project libbiosig Master Branch (ab0ee111)
Description An integer underflow vulnerability exists in the sopen FAMOS read functionality. A specially crafted .famos file can lead to an out-of-bounds write, which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For The Biosig Project libbiosig version 2.5.0, consider disabling the sopen FAMOS read functionality until a patch is available. For The Biosig Project libbiosig Master Branch (ab0ee111), consider disabling the sopen FAMOS read functionality until a patch is available. Avoid using specially crafted .famos files in the affected functionality to minimize the risk of exploitation.

Exploit

Fix

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2024-23313

Affected Products

Debian
Libbiosig