hashcat是hashcat团队的一款密码恢复工具。 hashcat 7.1.2及之前版本存在数字错误漏洞,该漏洞源于src/filehandling.c中的fgetl()函数在输入行恰好为缓冲区长度时,在调用方缓冲区之外写入一个字节的空终止符,导致越界堆写入,攻击者可通过提供包含恰好为HCBUFSIZ_LARGE字节行的哈希文件、potfile或wordlist触发该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68766 | 7.8 HIGH | hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection |
| CVE-2026-68768 | 6.1 MEDIUM | hashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized Username |
No comments yet