Lucene search

K
freebsdFreeBSDD2073237-5B52-11E3-80F7-C86000CBC6EC
HistoryNov 28, 2013 - 12:00 a.m.

OpenTTD -- Denial of service using forcefully crashed aircrafts

2013-11-2800:00:00
vuxml.freebsd.org
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.046

Percentile

92.7%

The OpenTTD Team reports:

The problem is caused by incorrectly handling the fact that
the aircraft circling the corner airport will be outside of the
bounds of the map. In the ‘out of fuel’ crash code the height
of the tile under the aircraft is determined. In this case
that means a tile outside of the allocated map array, which
could occasionally trigger invalid reads.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchopenttd= 0.3.6UNKNOWN
FreeBSDanynoarchopenttd< 1.3.3UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.046

Percentile

92.7%