漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
hashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token Field
Vulnerability Description
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, allowing a maximal input to write up to 44 bytes past the buffer boundary into adjacent esalt fields and heap chunk metadata, potentially enabling heap corruption or memory access violations.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
hashcat 缓冲区错误漏洞
Vulnerability Description
hashcat是hashcat团队的一款密码恢复工具。 hashcat 7.1.2之后版本存在缓冲区错误漏洞,该漏洞源于KeePass AESKDF/KDBX v4模块存在堆缓冲区溢出,未对第九个哈希字段令牌进行长度检查,导致攻击者可通过提供过大的第九个哈希字段令牌破坏相邻堆内存,可能导致堆损坏或内存访问违规。
CVSS Information
N/A
Vulnerability Type
N/A