Junglewise Threat Intelligence

Open Babel out-of-bounds write in PQS coord_file parser

Severity: critical · CVSS 9.8 · Published 2023-07-21

Technologies: openbabel (PyPI), Open Babel. Vendors: PyPI.

Executive brief

Open Babel is a widely used software library for converting and viewing chemical data files. A security vulnerability in how it handles certain file formats allows an attacker to execute malicious code by tricking the system into processing a specially crafted file. This could lead to a complete system takeover, data theft, or service disruption, especially for web-based chemical conversion services that use this library in their backend.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the PQS format coord_file parser within Open Babel. The root cause is an unsafe 'strcat' operation in 'formats/PQSformat.cpp' where a user-controlled string from a 'file=' parameter is concatenated to a fixed-size stack buffer ('full_coord_path') without sufficient bounds checking. An attacker can exploit this by providing a malformed PQS file, leading to a stack-based buffer overflow. While typically a local file-parsing issue, the vulnerability is rated critical (CVSS 9.8) because Open Babel is frequently used in networked backend services for automated chemical format conversion. The issue is patched in version 3.2.0.

Affected products

  • Open Babel Open Babel 3.1.1, master commit 530dbfa3, and all versions prior to 3.2.0

Timeline

  • 2023-07-21: advisory: Initial advisory published by Talos and GitHub
  • 2026-07-01: other: Advisory withdrawn as a duplicate of GHSA-f29h-2h58-48r7

References

Related threats