A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Libbiosig | Libbiosig_project | 2.5.0 (including) | 2.5.0 (including) | 
| Biosig | Ubuntu | mantic | * | 
| Biosig | Ubuntu | upstream | * |