A deserialization vulnerability in LevelChunkPacket
You guys forget to check the v6's value in LevelChunkPacket.
Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.
Here is my solution
Attachments2
Comments2
History5
Changed description:
You guys forget to check the v6's size in LevelChunkPacket.
0Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.
0Here is my solution
0

You guys forget to check the v6's size in LevelChunkPacket.
0Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.
0Here is my solution
00Changed description:
You guys forget to check the v6's
Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.
0Here is my solution
00You guys forget to check the v6's
Although it's direction is Server to Client, but some cheat clients like horion are using this vulnerability to crash Dedicated Server and Realms.
0Here is my solution
00Resolution: Unresolved β Awaiting Response
Resolution: Awaiting Response β Unresolved
Resolution: Unresolved β Incomplete


Thank you for your report!
However, this issue has been temporarily closed asΒ Awaiting Response
Can you please provide more details how to reproduce this issue?
Video would also be very helpful. You can record it and upload it here as attachment. If your video size exceeds 10 MB, you can use OneDrive or similar file hosting service and share link.
Also, just a reminder, to make your bug report as effective as possible, please try and include the following steps to reproduce the problem:
If your ticket does not look like the example givenΒ here, then it's likely to be closed as incomplete.
This ticket will automatically reopen when you reply.
Cleaning up old tickets: This ticket had been set to 'Awaiting Response', but has not received a response from the reporter (~3 months+) so is being closed as Incomplete. If you feel this is still a valid issue then please comment, or create a new ticket following the Issue Guidelines which includes steps to reproduce the problem.
Quick Links:
π Issue Guidelines β π¬ Mojang Support β π§ Suggestions β π Minecraft Wiki