github Pryaxis/TShock v4.3.25
TShock v4.3.25 for Terraria 1.3.5.3.

latest releases: v5.2.1, v5.2.0, v5.1.3...
7 years ago

This is a critical bug-fix release for TShock v4.3.24. It fixes a bug wherein a malicious payload sent by an attacker to the server could cause any number of the following effects:

  • Instantaneous crashing or lagging all clients.
  • Causing the server to enter an infinite loop (deadlock).
  • Chunks of the world may be corrupted permanently and saved to the disk.
  • General denial of service attacks.

If a client attempts this exploit, the API will disconnect them with the reason Disconnecting [player] (IP) for attempted packet length overflow crash/DoS attempt. It is highly suggested that any player caught doing this is immediately permanently banned. This fix does not take this action in order to prioritize getting the fix out as fast as possible.

If you have been using general-devel builds, the latest branch build of general-devel also includes this fix. If you have been using a custom version of TShock, you can safely just patch the Terraria Server executable and tick your own TShock version number appropriately.

Don't miss a new TShock release

NewReleases is sending notifications on new releases.