CVE Vulnerabilities

CVE-2024-23809

Double Free

Published: Feb 20, 2024 | Modified: Aug 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Weakness

The product calls free() twice on the same memory address.

Affected Software

Name Vendor Start Version End Version
Libbiosig Libbiosig_project 2.5.0 (including) 2.5.0 (including)
Biosig Ubuntu mantic *
Biosig Ubuntu upstream *

Potential Mitigations

References