Bug 853041 (CVE-2013-6411) - VUL-0: CVE-2013-6411: openttd: Denial of service (server) using forcefully crashed aircrafts
Summary: VUL-0: CVE-2013-6411: openttd: Denial of service (server) using forcefully cr...
Status: RESOLVED FIXED
Alias: CVE-2013-6411
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-30 09:47 UTC by Marcus Meissner
Modified: 2015-02-19 01:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-11-30 09:47:35 UTC
OSS:11571

CVE-2013-6411

Hello folks,

the OpenTTD team and contributors have discovered several a security
vulnerability in OpenTTD. Please be so kind to allocate a CVE id for
the issues detailed below:

Denial of service (server) using forcefully crashed aircrafts

A missing validation allows remote attackers to cause a denial of 
service (crash) by forcefully crashing aircraft near the corner of the 
map. This triggers a corner case where data outside of the allocated map 
array is accessed.

A test case, and simple guide how to reproduce it can be found in the 
issue in our bug tracker at http://bugs.openttd.org/task/5820

Vulnerability is present since 0.3.6 and will be fixed in the upcoming
1.3.3 release.

Once the CVE id is allocated, the issue will be fully documented at
http://security.openttd.org/en/CVE-2013-xxxx

Thanks,
Remko 'Rubidium' Bijker


References:
http://bugs.openttd.org/task/5820
http://security.openttd.org/en/CVE-2013-xxxx
http://comments.gmane.org/gmane.comp.security.oss.general/11571
Comment 1 Swamp Workflow Management 2013-11-30 23:00:27 UTC
bugbot adjusting priority
Comment 2 Forgotten User 0kSNykd7IH 2013-12-10 12:36:26 UTC
adding patch to openttd 1.2 from 12.2, updating openttd 1.3 to 1.3.3 from 12.3 and 13.1

(sorry for the delay, though this bug exists since almost 10 years, it should not hurt that much)
Comment 3 Bernhard Wiedemann 2013-12-10 13:00:24 UTC
This is an autogenerated message for OBS integration:
This bug (853041) was mentioned in
https://build.opensuse.org/request/show/210359 13.1+12.2+12.3 / openttd
Comment 4 Forgotten User 0kSNykd7IH 2013-12-10 13:13:17 UTC
factory submit: 161378
Comment 5 Sebastian Krahmer 2013-12-23 13:41:11 UTC
done
Comment 6 Swamp Workflow Management 2013-12-23 14:06:06 UTC
openSUSE-SU-2013:1932-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 853041
CVE References: CVE-2013-6411
Sources used:
openSUSE 13.1 (src):    openttd-1.3.3-2.4.1
openSUSE 12.3 (src):    openttd-1.3.3-2.8.1
openSUSE 12.2 (src):    openttd-1.2.2-2.8.1