Mojira Archive
MCPE-150817

Security vulnerability: Integer overflow in ClientCacheBlobStatusPacket::_read

When bedrock server deserializing ClientCacheBlobStatusPacket,there is a possible Integer overflow,which allows attackers to bypass the vector size check and allocate huge vector to exhaust server memory.

This vulnerability widely affects many versions(1.16.0-1.18.2) and even Minecraft Realms.

 

Incomplete

nt1dr

2021-12-16, 05:28 AM

2023-01-20, 05:52 PM

2023-01-20, 05:52 PM

0

1

Plausible

1.18.2 Hotfix

-