Mojira Archive
BDS-18231

A deserialization vulnerability in LevelChunkPacket

You guys forget to check the v6's value in LevelChunkPacket.

Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.

Here is my solution

Attachments2

photo_2023-03-25_18-41-49.jpg
photo_2023-03-25_18-41-49.jpg

Tony

photo_2023-03-25_19-25-33.jpg
photo_2023-03-25_19-25-33.jpg

Tony

Comments2

Thank you for your report!
However, this issue has been temporarily closed asΒ Awaiting Response

Can you please provide more details how to reproduce this issue?

Video would also be very helpful. You can record it and upload it here as attachment. If your video size exceeds 10 MB, you can use OneDrive or similar file hosting service and share link.

Also, just a reminder, to make your bug report as effective as possible, please try and include the following steps to reproduce the problem:

Steps to Reproduce:
1.
2.
3.

Observed Results:
(Briefly describe what happens)

Expected Results:
(Briefly describe what should happen)

If your ticket does not look like the example givenΒ here, then it's likely to be closed as incomplete.

This ticket will automatically reopen when you reply.

Cleaning up old tickets: This ticket had been set to 'Awaiting Response', but has not received a response from the reporter (~3 months+) so is being closed as Incomplete. If you feel this is still a valid issue then please comment, or create a new ticket following the Issue Guidelines which includes steps to reproduce the problem.

Quick Links:
πŸ““ Issue Guidelines – πŸ’¬ Mojang Support – πŸ“§ Suggestions – πŸ“– Minecraft Wiki

History5

[Bot] Arisa

Changed description:

You guys forget to check the v6's size in LevelChunkPacket.

0

Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.

0

Here is my solution

0

0

You guys forget to check the v6's size in LevelChunkPacket.

0

Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.

0

Here is my solution

0

0

Tony

Changed description:

You guys forget to check the v6's size in LevelChunkPacket.

0

Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.

0

Here is my solution

0

0

You guys forget to check the v6's value in LevelChunkPacket.

0

Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.

0

Here is my solution

0

0

Maciej Piornik

Resolution: Unresolved β†’ Awaiting Response

[MCQA] Kinga Izdebska

Resolution: Awaiting Response β†’ Unresolved

[MCQA] Kinga Izdebska

Resolution: Unresolved β†’ Incomplete

Incomplete
Tony
0
0
Unconfirmed
1.19.71