PT-2024-2170 · Libbiosig+1 · Libbiosig+1
Lilith >_>
·
Published
2024-02-20
·
Updated
2025-08-10
·
CVE-2024-23310
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libbiosig versions 2.5.0 through Master Branch (ab0ee111)
Description
A use-after-free vulnerability exists in the
sopen FAMOS read functionality. This issue can be triggered by a specially crafted .famos file, potentially leading to arbitrary code execution. An attacker can exploit this vulnerability by providing a malicious file.Recommendations
For libbiosig version 2.5.0, consider disabling the
sopen FAMOS read functionality until a patch is available.
For libbiosig Master Branch (ab0ee111), restrict the use of the sopen FAMOS read function to minimize the risk of exploitation.
Avoid using specially crafted .famos files with the affected sopen FAMOS read functionality until the issue is resolved.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Libbiosig