Critical severity9.8NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2022-42885
CVE-2022-42885
Description
A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openbabelPyPI | < 3.2.0 | 3.2.0 |
Affected products
4cpe:2.3:a:openbabel:open_babel:3.1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openbabel:open_babel:3.1.1:*:*:*:*:*:*:*
- (no CPE)range: <=3.1.1
- Open Babel/Open Babelv5Range: 3.1.1
Patches
Vulnerability mechanics
References
6- talosintelligence.com/vulnerability_reports/TALOS-2022-1668nvdExploitTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-mw5r-wq2m-397cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-42885ghsaADVISORY
- github.com/openbabel/openbabel/commit/fa9a2d9a2eb75154b7a884dfe679ff41a8f9c547ghsaWEB
- github.com/openbabel/openbabel/security/advisories/GHSA-mw5r-wq2m-397cghsaWEB
- www.talosintelligence.com/vulnerability_reports/TALOS-2022-1668nvdWEB
News mentions
0No linked articles in our index yet.