PT-2023-33069 · Unknown · Pocketmine-Mp
Published
2023-01-09
·
Updated
2023-01-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PocketMine-MP (affected versions not specified)
Description
The issue arises from the
DyeColorIdMap->fromId() function not handling invalid input properly, leading to an undefined offset error. This function is indirectly called during the deserialization of item NBT data, which can occur when receiving data from the network or disk. An attacker can exploit this by providing NBT data with invalid pattern color values in an inventory transaction or by using the /give command to obtain an item with malicious NBT data, potentially crashing a server.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pocketmine-Mp