top of page
perceptive_background_267k.jpg

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arb…

Published:

30 april 2026 om 22:00:00

Alert date:

1 mei 2026 om 20:05:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools

A heap-based buffer overflow vulnerability in hashcat v7.1.2's PKZIP hash parser allows attackers to cause denial of service or execute arbitrary code through crafted PKZIP hash files. The vulnerability exists in the hex_to_binary function where attacker-controlled hex data is decoded into a fixed-size buffer without proper input validation. The issue affects multiple hashcat modules (17200, 17210, 17220, 17225, and 17230) when data_type_enum is less than or equal to 1. This vulnerability poses a significant risk as it can lead to arbitrary code execution in a widely-used password recovery tool.

Technical details

Mitigation steps:

Affected products:

hashcat

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page