漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
hashcat through 7.1.2 Off-by-One Out-of-Bounds Heap Write in fgetl()
Vulnerability Description
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
Off-by-one错误
Vulnerability Title
hashcat 数字错误漏洞
Vulnerability Description
hashcat是hashcat团队的一款密码恢复工具。 hashcat 7.1.2及之前版本存在数字错误漏洞,该漏洞源于src/filehandling.c中的fgetl()函数在输入行恰好为缓冲区长度时,在调用方缓冲区之外写入一个字节的空终止符,导致越界堆写入,攻击者可通过提供包含恰好为HCBUFSIZ_LARGE字节行的哈希文件、potfile或wordlist触发该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A