Shockedplot7560

#36631de 56,326
7.5CVSS total
Vulnerabilidades · 1
PT-2026-88983
7.5
2023-07-14
Pmmp · Pocketmine-Mp · CVE-2023-54392
### Summary A player sending a packet can cause the server to crash by providing incorrect sign data in NBT in `BlockActorDataPacket`. ### Details This vulnerability was discovered using the `BlockActorDataPacket`, but other packets may also be affected. The player would seem to just need to send an NBT with an incorrect type to throw this error. ``` [Server thread/CRITICAL]: pocketmine btUnexpectedTagTypeException: "Expected a tag of type pocketmine bttagCompoundTag, got pocketmine bttagByteTag" (EXCEPTION) in "pmsrc/vendor/pocketmine/nbt/src/tag/CompoundTag" at line 107 --- Stack trace --- #0 pmsrc/src/network/mcpe/handler/InGamePacketHandler(751): pocketmine bttagCompoundTag->getCompoundTag(string[9] FrontText) #1 pmsrc/vendor/pocketmine/bedrock-protocol/src/BlockActorDataPacket(50): pocketmine etworkmcpehandlerInGamePacketHandler->handleBlockActorData(object pocketmine etworkmcpeprotocolBlockActorDataPacket#220241) #2 pmsrc/src/network/mcpe/NetworkSession(433): pocketmine etworkmcpeprotocolBlockActorDataPacket->handle(object pocketmine etworkmcpehandlerInGamePacketHandler#190572) ``` ### PoC Use a bot or proxy to send a packet when editing a sign. This packet should contain an NBT with incorrect types but correct architecture. ### Impact This makes it possible to shutdown a server for someone who knows how to operate it. As this was discovered in 4.22.1, everyone with at least this version is affected. ### Patches This bug was fixed by 0c250a2ef09627b48aa52302f6cc7e1f2afb70ea in the 4.22.3 and 5.2.1 releases. ### Workarounds A plugin may be able to handle `DataPacketReceiveEvent` for `BlockActorDataPacket`, and verify that the `FrontText` tag is a `TAG Compound`.