PT-2023-6136 · Unknown+1 · Open Babel+1

·

CVE-2022-46289

·

Published

2023-07-21

·

Updated

2026-07-13

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Open Babel versions 3.1.1 and prior
Description The issue is related to the nAtoms functionality in the ORCA format of Open Babel, which is associated with an out-of-bounds write operation in memory. This can be exploited by a remote attacker using a specially crafted file, potentially leading to arbitrary code execution. The nAtoms calculation can wrap around, resulting in a small buffer allocation.
Recommendations For Open Babel version 3.1.1, consider disabling the nAtoms functionality in the ORCA format until a patch is available. For versions prior to 3.1.1, restrict the use of the ORCA format to minimize the risk of exploitation. As a temporary workaround, avoid using the nAtoms functionality with untrusted or malicious files until the issue is resolved.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06842
CVE-2022-46289
GHSA-G8F4-G673-RFW2
GHSA-RJ4C-R689-CM87
OPENSUSE-SU-2026:21190-1
PYSEC-2026-2790

Affected Products

Debian
Open Babel