First published: Fri Jul 21 2023(Updated: )
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Babel | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46289 has a high severity due to its potential for arbitrary code execution through specially-crafted files.
To mitigate CVE-2022-46289, upgrade to the latest version of Open Babel that resolves the out-of-bounds write vulnerabilities.
CVE-2022-46289 can facilitate attacks leading to arbitrary code execution by exploiting vulnerabilities in the nAtoms functionality.
CVE-2022-46289 affects Open Babel 3.1.1 and any prior versions up to the fix.
If you are using a vulnerable version of Open Babel impacted by CVE-2022-46289, you should immediately update to the patched version to ensure your systems are secure.