Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgv2-whp7-2895

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.1

Описание

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

EPSS

Процентиль: 3%
0.00128
Низкий

6.9 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-193

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 дней назад

(hashcat's fgetl() function in src/filehandling.c writes a null termina ...)

CVSS3: 6.1
nvd
9 дней назад

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

CVSS3: 6.1
debian
9 дней назад

hashcat's fgetl() function in src/filehandling.c writes a null termina ...

EPSS

Процентиль: 3%
0.00128
Низкий

6.9 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-193