Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-20777

Опубликовано: 03 мар. 2026
Источник: debian

Описание

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
biosigunfixedpackage
biosigno-dsatrixiepackage
biosigno-dsabookwormpackage
biosigpostponedbullseyepackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2026-2362

  • Fixed by: https://sourceforge.net/p/biosig/code/ci/abe197c3627256ef3615a2d2f808ded069e1df4b/ (v3.9.3)

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.1
nvd
около 1 месяца назад

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.1
github
около 1 месяца назад

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость функциональности парсинга Nicolet WFT библиотеки обработки медицинских сигналов libbiosig, позволяющая нарушителю выполнить произвольный код