A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19409 A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 04:30:00 +0900


Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00702}

epss

{'score': 0.00951}


Fri, 14 Feb 2025 03:15:00 +0900

Type Values Removed Values Added
First Time appeared The Biosig Project
The Biosig Project libbiosig
CPEs cpe:2.3:a:the_biosig_project:libbiosig:2.5.0:*:*:*:*:*:*:*
Vendors & Products The Biosig Project
The Biosig Project libbiosig
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 04:00:00 +0900

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Libbiosig Project
Libbiosig Project libbiosig
Weaknesses CWE-787
CPEs cpe:2.3:a:libbiosig_project:libbiosig:2.5.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Libbiosig Project
Libbiosig Project libbiosig

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-11-04T18:22:59.634Z

Reserved: 2024-01-22T16:54:07.492Z

Link: CVE-2024-21795

cve-icon Vulnrichment

Updated: 2024-08-01T22:27:36.264Z

cve-icon NVD

Status : Modified

Published: 2024-02-20T16:15:08.130

Modified: 2025-11-04T19:16:30.263

Link: CVE-2024-21795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses