PocketMine-MP 在 3.26.5 之前和 4.0.5 之前的版本中,未对玩家提交的皮肤数据字段进行长度验证,导致无上限的值可能超过 32767 字节的 TAG_String 限制。攻击者可以提交过大的皮肤数据字段(如 skinID 或 geometryName),从而在 NBT 数据序列化过程中触发异常,导致服务器崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51013 | 6.5 MEDIUM | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51012 | 6.5 MEDIUM | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51018 | 6.5 MEDIUM | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51016 | 6.1 MEDIUM | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
| CVE-2022-51011 | 4.3 MEDIUM | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
No comments yet