CVE-2025-64736
Plain English Summary
AI-powered analysis for quick understanding
An attacker can exploit a flaw in the libbiosig library to read sensitive information from memory by using a specially crafted .abf file. This requires the victim to open the malicious file, which could lead to unauthorized access to private data.
Technical Description
An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 3, 2026
about 1 month ago
Last Modified
Mar 5, 2026
about 1 month ago
Vendor
libbiosig project
Product
libbiosig
Related Vulnerabilities
An attacker can execute arbitrary code on a system by tricking a user into opening a specially crafted Intan CLP file using the vulnerable version of the libbiosig library. This vulnerability requires the attacker to deliver the malicious file to the target, making it essential for users to be cautious about the files they open.
An attacker can execute arbitrary code on a system by tricking a user into opening a specially crafted .wft file using the affected version of the libbiosig library. This vulnerability occurs due to a flaw in how the library handles certain files, allowing the attacker to manipulate the program's memory.