CVE-2023-54396
Dashboard / Vulnerabilities / CVE-2023-54396
Summary: PocketMine-MP before 4.8.1 Server Crash via Banner NBT
Details: PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54396.json, https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-wqqv-jcfr-9f5g, https://nvd.nist.gov/vuln/detail/CVE-2023-54396, https://www.vulncheck.com/advisories/pocketmine-mp-before-4.8.1-server-crash-via-banner-nbt, https://github.com/pmmp/PocketMine-MP/commit/08b9495bce2d65a6d1d3eeb76e484499a00765eb
Affected packages
Package
Name:
Purl:
