Bugzilla – Bug 853041
VUL-0: CVE-2013-6411: openttd: Denial of service (server) using forcefully crashed aircrafts
Last modified: 2015-02-19 01:35:00 UTC
OSS:11571 CVE-2013-6411 Hello folks, the OpenTTD team and contributors have discovered several a security vulnerability in OpenTTD. Please be so kind to allocate a CVE id for the issues detailed below: Denial of service (server) using forcefully crashed aircrafts A missing validation allows remote attackers to cause a denial of service (crash) by forcefully crashing aircraft near the corner of the map. This triggers a corner case where data outside of the allocated map array is accessed. A test case, and simple guide how to reproduce it can be found in the issue in our bug tracker at http://bugs.openttd.org/task/5820 Vulnerability is present since 0.3.6 and will be fixed in the upcoming 1.3.3 release. Once the CVE id is allocated, the issue will be fully documented at http://security.openttd.org/en/CVE-2013-xxxx Thanks, Remko 'Rubidium' Bijker References: http://bugs.openttd.org/task/5820 http://security.openttd.org/en/CVE-2013-xxxx http://comments.gmane.org/gmane.comp.security.oss.general/11571
bugbot adjusting priority
adding patch to openttd 1.2 from 12.2, updating openttd 1.3 to 1.3.3 from 12.3 and 13.1 (sorry for the delay, though this bug exists since almost 10 years, it should not hurt that much)
This is an autogenerated message for OBS integration: This bug (853041) was mentioned in https://build.opensuse.org/request/show/210359 13.1+12.2+12.3 / openttd
factory submit: 161378
done
openSUSE-SU-2013:1932-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 853041 CVE References: CVE-2013-6411 Sources used: openSUSE 13.1 (src): openttd-1.3.3-2.4.1 openSUSE 12.3 (src): openttd-1.3.3-2.8.1 openSUSE 12.2 (src): openttd-1.2.2-2.8.1