Stack-Based Buffer Overflow in Libbiosig by Biosig Project
CVE-2025-54487
9.8CRITICAL
What is CVE-2025-54487?
A buffer overflow vulnerability is present in the MFER file parsing functionality of the libbiosig library. Specifically, the issue arises when processing MFER files with a Tag value of 12, where improper length checks lead to unsafe memory operations. Attackers can exploit this condition by providing specially crafted MFER files, resulting in potential arbitrary code execution. The vulnerability is triggered by values of 'len' exceeding 130 or being less than 2, leading to significant security risks. Developers and users of the affected versions are urged to apply necessary patches to mitigate the risk.
Affected Version(s)
libbiosig 3.9.0
libbiosig Master Branch (35a819fa)
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Mark Bereza and Lilith >_> of Cisco Talos.