Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
hashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token Field
Vulnerability Description
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, allowing a maximal input to write up to 44 bytes past the buffer boundary into adjacent esalt fields and heap chunk metadata, potentially enabling heap corruption or memory access violations.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
hashcat 缓冲区错误漏洞
Vulnerability Description
hashcat是hashcat团队的一款密码恢复工具。 hashcat 7.1.2之后版本存在缓冲区错误漏洞,该漏洞源于KeePass AESKDF/KDBX v4模块存在堆缓冲区溢出,未对第九个哈希字段令牌进行长度检查,导致攻击者可通过提供过大的第九个哈希字段令牌破坏相邻堆内存,可能导致堆损坏或内存访问违规。
CVSS Information
N/A
Vulnerability Type
N/A