Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r3q-94wc-xhq9

Опубликовано: 21 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Duplicate Advisory: Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7h6r-6p76-68c9. This link is maintained to preserve external references.

Original Description

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC file format, inside the Final Point and Derivatives section

Пакеты

Наименование

openbabel

pip
Затронутые версииВерсия исправления

< 3.2.0

3.2.0

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-787

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-787