|
|
| |
|
| |
openttd: arbitrary code execution
| Package(s): | openttd |
CVE #(s): | CVE-2008-3547
CVE-2008-3576
CVE-2008-3577
|
| Created: | March 9, 2009 |
Updated: | March 11, 2009 |
| Description: |
From the Gentoo advisory:
Multiple buffer overflows have been reported in OpenTTD, when storing
long for client names (CVE-2008-3547), in the TruncateString function
in src/gfx.cpp (CVE-2008-3576) and in src/openttd.cpp when processing a
large filename supplied to the "-g" parameter in the ttd_main function
(CVE-2008-3577).
An authenticated attacker could exploit these vulnerabilities to
execute arbitrary code with the privileges of the OpenTTD server.
|
| Alerts: |
|
( Log in to post comments)
|
|
|