PT-2023-6136 · Unknown+1 · Open Babel+1

·

CVE-2022-46289

·

Publicado

2023-07-21

·

Atualizado

2026-07-13

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Open Babel versions 3.1.1 and prior
Description The issue is related to the nAtoms functionality in the ORCA format of Open Babel, which is associated with an out-of-bounds write operation in memory. This can be exploited by a remote attacker using a specially crafted file, potentially leading to arbitrary code execution. The nAtoms calculation can wrap around, resulting in a small buffer allocation.
Recommendations For Open Babel version 3.1.1, consider disabling the nAtoms functionality in the ORCA format until a patch is available. For versions prior to 3.1.1, restrict the use of the ORCA format to minimize the risk of exploitation. As a temporary workaround, avoid using the nAtoms functionality with untrusted or malicious files until the issue is resolved.

Exploit

Correção

Heap Based Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06842
CVE-2022-46289
GHSA-G8F4-G673-RFW2
GHSA-RJ4C-R689-CM87
OPENSUSE-SU-2026:21190-1
PYSEC-2026-2790

Produtos afetados

Debian
Open Babel