Mojira Archive
MCPE-150816

Security vulnerability: NULL pointer dereference in ServerNetworkHandler::handle(DisconnectPacket)

Bedrock Server does not handle DisconnectPacket correctly. When a client establish a connection to the server but does not send loginPacket,sending DisconnectPacket can trigger a NULL pointer dereference in ServerNetworkHandler::handle(DisconnectPacket), which will crash the server.

The vulnerability widely affects many versions(1.18.2 and earlier) of Bedrock Server.

Duplicate

nt1dr

2021-12-16, 05:22 AM

2022-01-13, 03:28 PM

2022-01-13, 03:28 PM

0

1

Plausible

1.18.2 Hotfix

-