PT-2026-88988 · Pmmp+2 · Pocketmine-Mp+1

·

CVE-2024-58380

·

Publicado

2024-03-06

·

Atualizado

2026-09-09

CVSS v4.0
CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Summary

If a client sends a BookEditPacket with InventorySlot greater than 35, the server will crash due to an unhandled exception thrown by BaseInventory->getItem().

Details

PoC

Using Gophertunnel, use serverConn.WritePacket(&packet.BookEdit{InventorySlot: 36})

Impact

Server crash, all servers

Patched versions

This issue was fixed by 47f011966092f275cc1b11f8de635e89fd9651a7, and the fix was released in 5.11.2.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-58380
GHSA-XC7J-WJ36-QJFR

Produtos afetados

Pocketmine-Mp
Pocketmine/Pocketmine-Mp