Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2705

Опубликовано: 19 фев. 2026
Источник: debian
EPSS Низкий

Описание

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openbabelfixed3.2.0+dfsg-1~expexperimentalpackage
openbabelunfixedpackage
openbabelno-dsatrixiepackage
openbabelno-dsabookwormpackage
openbabelpostponedbullseyepackage

Примечания

  • https://github.com/openbabel/openbabel/issues/2848

  • https://github.com/openbabel/openbabel/pull/2862

  • Fixed by: https://github.com/openbabel/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a

EPSS

Процентиль: 49%
0.007
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 месяцев назад

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
nvd
6 месяцев назад

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The patch is identified as e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.5
github
около 1 месяца назад

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

CVSS3: 8.1
fstec
6 месяцев назад

Уязвимость компонента MOL2 File Handler программного обеспечения преобразования форматов файлов химических веществ Open Babel, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
redos
4 месяца назад

Уязвимость openbabel

EPSS

Процентиль: 49%
0.007
Низкий