PT-2010-4087 · Openttd Team · Openttd

Publicado

2010-07-27

·

Atualizado

2017-08-17

·

CVE-2010-2534

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenTTD versions prior to 1.0.3
Description The issue is related to the NetworkSyncCommandQueue function in network/network command.cpp, which does not properly clear a pointer in a linked list. This allows remote attackers to cause a denial of service, resulting in an infinite loop and CPU consumption, via a crafted request related to the client command queue.
Recommendations For versions prior to 1.0.3, update to version 1.0.3 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2534

Produtos afetados

Openttd