Executive brief
Open Babel, a widely used library for processing chemistry file formats, contains a memory safety flaw in its ORCA file parser. An attacker could provide a specially crafted chemistry file that, when opened by a user or processed by a service using this library, could lead to unauthorized code execution or system crashes. This affects various applications and web services that rely on Open Babel to convert or view molecular data.
Technical details
An out-of-bounds write vulnerability (CWE-787/CWE-122) exists in Open Babel's ORCA format parser within the 'nAtoms' functionality. The vulnerability occurs in 'formats/orcaformat.cpp' where the parser reads the number of atoms from a file and subsequently fills a coordinate buffer without verifying that the input index remains within the allocated bounds of the 'nAtoms' variable. An attacker can trigger this by providing a malformed ORCA file with a mismatched atom count and coordinate list. The exploit requires local user interaction (opening a file) or a service that processes untrusted ORCA files. The issue is patched in version 3.2.0.
Affected products
- Open Babel Open Babel <= 3.1.1
Timeline
- 2023-07-21: disclosed: Initial report by Cisco Talos
- 2026-05-26: patched: Version 3.2.0 released
- 2026-07-01: advisory: GitHub Advisory published
References
- https://github.com/openbabel/openbabel/security/advisories/GHSA-5rff-8f7c-8jmw
- https://github.com/openbabel/openbabel/commit/b239d06eb724bb684eea0040e9d87cf07072b081
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1665
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1665
- https://api.github.com/repos/openbabel/openbabel/security-advisories/GHSA-5rff-8f7c-8jmw