Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-21795
HistoryFeb 20, 2024 - 12:00 a.m.

CVE-2024-21795

2024-02-2000:00:00
ubuntu.com
ubuntu.com
16
heap-based
buffer overflow
libbiosig

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

39.1%

A heap-based buffer overflow vulnerability exists in the .egi parsing
functionality of The Biosig Project libbiosig 2.5.0 and Master Branch
(ab0ee111). A specially crafted .egi file can lead to arbitrary code
execution. An attacker can provide a malicious file to trigger this
vulnerability.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchbiosig< anyUNKNOWN
ubuntu24.04noarchbiosig< anyUNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

39.1%