FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

OpenTTD -- Denial of service (server/client) via invalid read

Affected packages
1.0.0 <= openttd < 1.0.5

Details

VuXML ID 373e412e-f748-11df-96cd-0015f2db7bde
Discovery 2010-11-20
Entry 2010-11-23

The OpenTTD Team reports:

When a client disconnects, without sending the "quit" or "client error" message, the server has a chance of reading and writing a just freed piece of memory. The writing can only happen while the server is sending the map. Depending on what happens directly after freeing the memory there is a chance of segmentation fault, and thus a denial of service.

References

CVE Name CVE-2010-4168
URL http://security.openttd.org/en/CVE-2010-4168