原始 OSV JSON{
"id": "GHSA-5fgf-q57f-wwqf",
"aliases": [],
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pp85-5j63-xpq3. This link is maintained to preserve external references.\n\n## Original Description\nA weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after free. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.",
"summary": "Duplicate Advisory: Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.2.0"
}
]
}
],
"package": {
"name": "openbabel",
"ecosystem": "PyPI"
}
}
],
"modified": "2026-06-30T18:48:51Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"published": "2025-09-26T03:31:07Z",
"withdrawn": "2026-06-30T18:48:51Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10994",
"type": "ADVISORY"
},
{
"url": "https://github.com/openbabel/openbabel/issues/2834",
"type": "WEB"
},
{
"url": "https://github.com/user-attachments/files/22318611/poc.zip",
"type": "WEB"
},
{
"url": "https://vuldb.com/?ctiid.325922",
"type": "WEB"
},
{
"url": "https://vuldb.com/?id.325922",
"type": "WEB"
},
{
"url": "https://vuldb.com/?submit.654057",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "LOW",
"github_reviewed": true,
"nvd_published_at": "2025-09-26T02:15:52Z",
"github_reviewed_at": "2026-06-30T18:48:51Z"
}
}