PT-2024-2170 · Libbiosig+1 · Libbiosig+1

Lilith >_>

·

Published

2024-02-20

·

Updated

2025-08-10

·

CVE-2024-23310

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libbiosig versions 2.5.0 through Master Branch (ab0ee111)
Description A use-after-free vulnerability exists in the sopen FAMOS read functionality. This issue can be triggered by a specially crafted .famos file, potentially leading to arbitrary code execution. An attacker can exploit this vulnerability by providing a malicious file.
Recommendations For libbiosig version 2.5.0, consider disabling the sopen FAMOS read functionality until a patch is available. For libbiosig Master Branch (ab0ee111), restrict the use of the sopen FAMOS read function to minimize the risk of exploitation. Avoid using specially crafted .famos files with the affected sopen FAMOS read functionality until the issue is resolved.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-02084
CVE-2024-23310

Affected Products

Debian
Libbiosig