PocketMine-MP 在 3.18.1 之前的版本未能对 MovePlayerPacket 中 position 和 rotation 字段的 NaN 或 INF 值进行校验。恶意客户端可以发送包含非法浮点数值(如 NaN 或 INF)的移动数据包,从而通过未处理的数学运算导致服务器崩溃,或阻止客户端渲染其他玩家。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | < 3.18.1 |
affected |
3.18.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 3.18.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51009 | 7.5 HIGH | PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry |
| CVE-2020-37277 | 6.5 MEDIUM | PocketMine-MP before 3.15.4 Denial of Service via InventoryTransaction |
| CVE-2022-51008 | 5.3 MEDIUM | PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions |
| CVE-2021-48006 | 3.3 LOW | PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity |
No comments yet