PT-2024-2159 · Libbiosig+1 · Libbiosig+1
Lilith >_>
·
Published
2024-02-20
·
Updated
2025-01-22
·
CVE-2024-23809
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libbiosig versions 2.5.0 and Master Branch (ab0ee111)
Description
A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of libbiosig. This issue is related to an error in memory deallocation. Exploitation of this vulnerability can allow a remote attacker to execute arbitrary code using a specially crafted .vdhr file.
Recommendations
For libbiosig version 2.5.0, consider disabling the BrainVision ASCII Header Parsing functionality until a patch is available.
For libbiosig Master Branch (ab0ee111), restrict access to the .vdhr file parsing functionality to minimize the risk of exploitation.
Avoid using specially crafted .vdhr files until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Libbiosig