MEDIUM 4.3 PyPI
Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
GHSA-3f56-w4g2-mx64
Published · Modified
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4w5w-4fhm-q483. This link is maintained to preserve external references.
Original Description
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-2705
- WEB https://github.com/openbabel/openbabel/issues/2848
- WEB https://github.com/openbabel/openbabel/pull/2862
- WEB https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a
- WEB https://github.com/oneafter/0128/blob/main/ob2/repro.mol2
- WEB https://vuldb.com/?ctiid.346651
- WEB https://vuldb.com/?id.346651
- WEB https://vuldb.com/?submit.754379
Ready to move
Start Securing
Free, no credit card | First findings in minutes