hashcat 在解析恢复文件时未能正确限制命令行选项,攻击者可以利用这一点注入用于输出重定向的选项(例如 和 )。攻击者可以构造包含恶意选项的恢复文件,将受其控制的内容追加到任意文件中。当目标文件为 shell 启动文件时,这将导致代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-68767 | 6.1 MEDIUM | hashcat through 7.1.2 Off-by-One Out-of-Bounds Heap Write in fgetl() |
| CVE-2026-68768 | 6.1 MEDIUM | hashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized Username |
No comments yet