OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
BID:39874
Info
OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
| Bugtraq ID: | 39874 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0406 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2010 12:00AM |
| Updated: | Apr 13 2015 08:15PM |
| Credit: | Zdenek Sojka (SmatZ) |
| Vulnerable: |
OpenTTD OpenTTD 1.0 OpenTTD OpenTTD 0.7.5 OpenTTD OpenTTD 0.7.4 OpenTTD OpenTTD 0.6.3 OpenTTD OpenTTD 0.6.2 OpenTTD OpenTTD 0.6.1 OpenTTD OpenTTD 0.5.3 OpenTTD OpenTTD 0.5.1 OpenTTD OpenTTD 0.5 OpenTTD OpenTTD 0.4.7 OpenTTD OpenTTD 0.4 .0.1 OpenTTD OpenTTD 0.3.5 OpenTTD OpenTTD 0.7 |
| Not Vulnerable: |
OpenTTD OpenTTD 1.0.1 |
Discussion
OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
OpenTTD is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue will allow remote attackers to crash the affected application, denying service to legitimate users.
Versions prior to OpenTTD 1.0.1 are vulnerable.
OpenTTD is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue will allow remote attackers to crash the affected application, denying service to legitimate users.
Versions prior to OpenTTD 1.0.1 are vulnerable.
Exploit / POC
OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
OpenTTD OpenTTD 0.7
OpenTTD OpenTTD 0.3.5
OpenTTD OpenTTD 0.4 .0.1
OpenTTD OpenTTD 0.4.7
OpenTTD OpenTTD 0.5
OpenTTD OpenTTD 0.5.1
OpenTTD OpenTTD 0.5.3
OpenTTD OpenTTD 0.6.1
OpenTTD OpenTTD 0.6.2
OpenTTD OpenTTD 0.6.3
OpenTTD OpenTTD 0.7.4
OpenTTD OpenTTD 0.7.5
OpenTTD OpenTTD 1.0
Solution:
Updates are available. Please see the references for more information.
OpenTTD OpenTTD 0.7
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 0.3.5
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.4 .0.1
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.4.7
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.5
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.5.1
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.5.3
-
OpenTTD 26.patch
http://security.openttd.org/en/patch/26.patch
OpenTTD OpenTTD 0.6.1
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 0.6.2
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 0.6.3
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 0.7.4
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 0.7.5
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
OpenTTD OpenTTD 1.0
-
OpenTTD 25.patch
http://security.openttd.org/en/patch/25.patch
References
OpenTTD Map Download File Descriptor Consumption Remote Denial of Service Vulnerability
References:
References:
- CVE-2010-0406 (vulnerable 0.3.5 - fixed 1.0.1) (OpenTTD)
- OpenTTD Homepage (OpenTTD)