LWN.net Logo

openttd: multiple vulnerabilities

Package(s):openttd CVE #(s):CVE-2011-3341 CVE-2011-3342 CVE-2011-3343
Created:September 20, 2011 Updated:January 12, 2012
Description: From the CVE entries:

Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted CMD_INSERT_ORDER command. (CVE-2011-3341)

Multiple buffer overflows in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors related to (1) NAME, (2) PLYR, (3) CHTS, or (4) AIPL (aka AI config) chunk loading from a savegame. (CVE-2011-3342)

Multiple buffer overflows in OpenTTD before 1.1.3 allow local users to cause a denial of service (daemon crash) or possibly gain privileges via (1) a crafted BMP file with RLE compression or (2) crafted dimensions in a BMP file. (CVE-2011-3343)

Alerts:
Gentoo 201111-03 2011-11-11
Fedora FEDORA-2011-12975 2011-09-19
Debian DSA-2386-1 2012-01-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds