Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

numerous vulnerabilities reported by cisco TALOS #2650

Open
ajakk opened this issue Nov 25, 2023 · 4 comments
Open

numerous vulnerabilities reported by cisco TALOS #2650

ajakk opened this issue Nov 25, 2023 · 4 comments

Comments

Copy link

welcome bot commented Nov 25, 2023

Thanks for opening your first issue here! Be sure to follow the issue template!

@ajakk ajakk changed the title numerous numerous vulnerabilities reported by cisco TALOS Nov 25, 2023
@ghutchis
Copy link
Member

ghutchis commented Nov 26, 2023

Cisco contacted me with a short window to fix these. Considering openbabel is used primarily in informatics, I'm not sure what some of these vulnerabilities get you.

You craft a specific Gaussian output file that allows you to hijack the obabel process. And do what, exactly? Execute something as the current user?

I don't want to downplay these - they're definitely bugs and should be fixed before the next release. But obabel is also a cheminformatics library, not generally facing an open network.

@baoilleach
Copy link
Member

I guess a potential attack vector would be If someone were running a publicly exposed webapp that did conversions, and an attacker combined it with a privilege escalation vulnerability, they would have control of the server.

@mbanck
Copy link
Contributor

mbanck commented Dec 22, 2023

This has been brought up by the Debian security team as well: https://bugs.debian.org/1059277

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants