Mojira Archive
MCPE-121418

Critical vulnerability, turing complete code inside Resource Packs gets executed by MC.

In the appended Resource Pack, there are two files containing C++ code which can possibly be exploited. Although this technically isn't a bug, it is a high security risk because the code executes inside of Minecraft. I plan on doing a proof-of-concept, but the goal is to fix vulnerabilities before they get exploited. So far, downloading resource packs hasn't ever really been a risk, unless of course you executed any contained code. Minecraft itself never called anything that could do damage without buffer overflow. Since this resource pack works on my PC and mobile (Android) and my friends iPad, the vulnerability really is a big deal.

Incomplete

Iamnot Tellingmyname

2021-03-16, 05:11 PM

2021-06-29, 11:02 AM

2021-06-29, 11:02 AM

1

3

Unconfirmed

1.16.210

-