Junglewise Threat Intelligence

Open Babel out-of-bounds write in ORCA nAtoms parser

Severity: critical · CVSS 9.8 · Published 2023-07-21

Technologies: Open Babel, openbabel (PyPI). Vendors: PyPI.

Executive brief

Open Babel, a widely used library for converting chemical data formats, contains a security flaw in how it processes ORCA files. By providing a specially crafted, malicious file to a system using this library (such as an online molecule viewer or converter), an attacker could potentially take control of the system or cause it to crash. This could lead to unauthorized access to data or a disruption of services that rely on Open Babel for chemical data processing.

Technical details

Multiple out-of-bounds write vulnerabilities (CWE-787, CWE-122) exist in the ORCA format nAtoms functionality within 'formats/orcaformat.cpp' of Open Babel. The first variant (CVE-2022-46289) involves an integer overflow when calculating the size for the 'confCoords' heap buffer (nAtoms * 3), leading to a smaller-than-required allocation. The second variant (CVE-2022-46290) involves a loop that stores coordinates into this buffer without verifying the current index against the 'nAtoms' value. An attacker can exploit these by providing a malformed ORCA file with a large 'nAtoms' value or excessive coordinate entries, resulting in a heap-based buffer overflow. This can be triggered remotely if the library is used in network-accessible services like web-based chemical converters. The issue is resolved in version 3.2.0.

Affected products

  • Open Babel Open Babel 3.1.1, master commit 530dbfa3, all versions before 3.2.0

Timeline

  • 2023-07-21: advisory: Initial Talos and NVD disclosure
  • 2026-07-01: other: Advisory GHSA-wj42-v2p3-fq2w withdrawn as a duplicate of GHSA-5rff-8f7c-8jmw

References

Related threats