{"id":"GHSA-5jfw-35xp-5m42","summary":"Buffer length underflow in LoginPacket causing unchecked exceptions to be thrown","details":"### Impact\n`LoginPacket` uses `BinaryStream-\u003egetLInt()` to read the lengths of JSON payloads it wants to decode. Unfortunately, `BinaryStream-\u003egetLInt()` returns a signed integer, meaning that a malicious client can craft a packet with a large uint32 value for payload buffer size (which would be interpreted as a negative signed int32), causing `BinaryStream-\u003eget()` to throw an exception.\n\nIn the context of PocketMine-MP, this leads to a server crash when the vulnerability is exploited.\n\n### Patches\ne3fce7632b94e83fd6a518a87dcaf6a11681c4ac\n\n### Workarounds\nThis can be worked around by registering a custom `LoginPacket` implementation into `PacketPool` which overrides [this code](https://github.com/pmmp/BedrockProtocol/blob/47532c95ea37d5f0365b23f734d70d943ff95295/src/LoginPacket.php#L54) to patch it.\n\n### For more information\n* Email us at [team@pmmp.io](mailto:team@pmmp.io)","modified":"2024-12-05T05:39:20.852353Z","published":"2022-04-05T17:53:22Z","database_specific":{"github_reviewed_at":"2022-04-05T17:53:22Z","nvd_published_at":null,"cwe_ids":["CWE-124"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pmmp/BedrockProtocol/security/advisories/GHSA-5jfw-35xp-5m42"},{"type":"WEB","url":"https://github.com/pmmp/BedrockProtocol/commit/e3fce7632b94e83fd6a518a87dcaf6a11681c4ac"},{"type":"PACKAGE","url":"https://github.com/pmmp/BedrockProtocol"}],"affected":[{"package":{"name":"pocketmine/bedrock-protocol","ecosystem":"Packagist","purl":"pkg:composer/pocketmine/bedrock-protocol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.2"}]}],"versions":["1.0.0+bedrock-1.17.10","1.1.0+bedrock-1.17.10","2.0.0+bedrock-1.17.30","3.0.0+bedrock-1.17.40","3.0.1+bedrock-1.17.40","3.0.2+bedrock-1.17.40","4.0.0+bedrock-1.17.40","4.0.1+bedrock-1.17.40","5.0.0+bedrock-1.17.40","5.1.0+bedrock-1.17.40","5.1.1+bedrock-1.17.40","5.1.2+bedrock-1.17.40","5.1.3+bedrock-1.17.40","6.0.0+bedrock-1.17.40","7.0.0+bedrock-1.18.0","7.1.0+bedrock-1.18.0","7.2.0+bedrock-1.18.0","7.3.0+bedrock-1.18.0","7.3.1+bedrock-1.18.0","8.0.0+bedrock-1.18.10","8.0.1+bedrock-1.18.10","8.0.2+bedrock-1.18.10"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5jfw-35xp-5m42/GHSA-5jfw-35xp-5m42.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}