LWN.net Logo

openttd: arbitrary code execution

Package(s):openttd CVE #(s):CVE-2008-3547 CVE-2008-3576 CVE-2008-3577
Created:March 9, 2009 Updated:March 11, 2009
Description:

From the Gentoo advisory:

Multiple buffer overflows have been reported in OpenTTD, when storing long for client names (CVE-2008-3547), in the TruncateString function in src/gfx.cpp (CVE-2008-3576) and in src/openttd.cpp when processing a large filename supplied to the "-g" parameter in the ttd_main function (CVE-2008-3577).

An authenticated attacker could exploit these vulnerabilities to execute arbitrary code with the privileges of the OpenTTD server.

Alerts:
Gentoo 200903-09 2009-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds