GHSA-556r-f58w-q4pfHighCVSS 6.5
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket...
🔗 CVE IDs covered (1)
📋 Description
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.
🔗 References (5)
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-fm35-jgg3-3grx
- https://nvd.nist.gov/vuln/detail/CVE-2021-48007
- https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638
- https://www.vulncheck.com/advisories/pocketmine-mp-before-3.18.1-denial-of-service-via-moveplayerpacket
- https://github.com/advisories/GHSA-556r-f58w-q4pf