GMS-2022-454: NaN/INF in serverbound movement packets can crash clients and servers
(updated )
A malicious client may send a MovePlayerPacket
to the server whose position or rotation contains NaN or INF. Since neither the server nor vanilla client handles this properly, a number of interesting side effects come into play.
References
Detect and mitigate GMS-2022-454 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →