PocketMine-MP 在 4.2.10 之前未能验证传入聊天消息数据块的总长度(即在按换行符拆分前),攻击者可以发送包含大量换行符的大型消息。恶意客户端可以发送兆字节大小的聊天数据包,并用成千上万个此类消息轰炸服务器,导致服务器出现持续数秒乃至数分钟的卡顿(锁死)现象。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | < 4.2.10 |
affected |
4.2.10 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 4.2.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51017 | 7.5 HIGH | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2022-51013 | 6.5 MEDIUM | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51012 | 6.5 MEDIUM | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51018 | 6.5 MEDIUM | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51016 | 6.1 MEDIUM | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
No comments yet