OpenTTD Multiple Unspecified Format String Vulnerabilities
BID:14738
Info
OpenTTD Multiple Unspecified Format String Vulnerabilities
| Bugtraq ID: | 14738 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2763 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovered by Alexey Dobriyan. |
| Vulnerable: |
OpenTTD OpenTTD 0.4 .0.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
OpenTTD Multiple Unspecified Format String Vulnerabilities
OpenTTD is prone to multiple format string vulnerabilities. Successful exploitation could cause the application to fail or allow remote arbitrary code execution.
OpenTTD is prone to multiple format string vulnerabilities. Successful exploitation could cause the application to fail or allow remote arbitrary code execution.
Exploit / POC
OpenTTD Multiple Unspecified Format String Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenTTD Multiple Unspecified Format String Vulnerabilities
Solution:
Gentoo has released advisory GLSA 200509-03 to address this issue. To obtain fixes, execute the following as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=games-simulation/openttd-0.4.0.1-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released advisory GLSA 200509-03 to address this issue. To obtain fixes, execute the following as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=games-simulation/openttd-0.4.0.1-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.