Bug 1217676 (CVE-2022-37331) - VUL-0: openbabel: Multiple openbabel vulnerabilities
Summary: VUL-0: openbabel: Multiple openbabel vulnerabilities
Status: NEW
Alias: CVE-2022-37331
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Martin Pluskal
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/373222/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-30 04:21 UTC by SMASH SMASH
Modified: 2023-11-30 05:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-11-30 04:21:38 UTC
An out-of-bounds write vulnerability exists in the Gaussian format orientation
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37331
Comment 1 Stoyan Manolov 2023-11-30 04:27:19 UTC
An out-of-bounds write vulnerability exists in the CSR format title
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41793

-

A use of uninitialized pointer vulnerability exists in the GRO format res
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-42885

-

An out-of-bounds write vulnerability exists in the PQS format coord_file
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-43467

-

An out-of-bounds write vulnerability exists in the MOL2 format attribute and
value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-43607

-

A use of uninitialized pointer vulnerability exists in the MSI format atom
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-44451

-

A use of uninitialized pointer vulnerability exists in the PQS format pFormat
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially
crafted malformed file can lead to arbitrary code execution. An attacker can
provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46280

-

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A
specially-crafted malformed file can lead to arbitrary code execution. An
attacker can provide a malicious file to trigger this vulnerability.nAtoms
calculation wrap-around, leading to a small buffer allocation

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46289

-

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms
functionality of Open Babel 3.1.1 and master commit 530dbfa3. A
specially-crafted malformed file can lead to arbitrary code execution. An
attacker can provide a malicious file to trigger this vulnerability.The loop
that stores the coordinates does not check its index against nAtoms

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46290

-

Multiple out-of-bounds write vulnerabilities exist in the translationVectors
parsing functionality in multiple supported formats of Open Babel 3.1.1 and
master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary
code execution. An attacker can provide a malicious file to trigger this
vulnerability.This vulnerability affects the MSI file format

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46291

-

Multiple out-of-bounds write vulnerabilities exist in the translationVectors
parsing functionality in multiple supported formats of Open Babel 3.1.1 and
master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary
code execution. An attacker can provide a malicious file to trigger this
vulnerability.This vulnerability affects the MOPAC file format, inside the Unit
Cell Translation section

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46292

-

Multiple out-of-bounds write vulnerabilities exist in the translationVectors
parsing functionality in multiple supported formats of Open Babel 3.1.1 and
master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary
code execution. An attacker can provide a malicious file to trigger this
vulnerability.This vulnerability affects the MOPAC file format, inside the Final
Point and Derivatives section

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46293

-

Multiple out-of-bounds write vulnerabilities exist in the translationVectors
parsing functionality in multiple supported formats of Open Babel 3.1.1 and
master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary
code execution. An attacker can provide a malicious file to trigger this
vulnerability.This vulnerability affects the MOPAC Cartesian file format

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46294

-

Multiple out-of-bounds write vulnerabilities exist in the translationVectors
parsing functionality in multiple supported formats of Open Babel 3.1.1 and
master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary
code execution. An attacker can provide a malicious file to trigger this
vulnerability.This vulnerability affects the Gaussian file format

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46295