Upstream information

CVE-2022-46295 at MITRE

Description

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the Gaussian file format

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v3 Scores
CVSS detail CNA (Talos) National Vulnerability Database
Base Score 9.8 7.8
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Network Local
Attack Complexity Low Low
Privileges Required None None
User Interaction None Required
Scope Unchanged Unchanged
Confidentiality Impact High High
Integrity Impact High High
Availability Impact High High
CVSSv3 Version 3.1 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • libopenbabel8 >= 3.2.0-1.1
  • openbabel >= 3.2.0-1.1
  • openbabel-devel >= 3.2.0-1.1
  • openbabel-gui >= 3.2.0-1.1
  • python3-openbabel >= 3.2.0-1.1
Patchnames:
openSUSE-Tumbleweed-2026-10936


SUSE Timeline for this CVE

CVE page created: Sat Jul 22 02:03:01 2023
CVE page last modified: Wed Jun 3 11:17:24 2026