FreeBSD : OpenTTD -- Denial of service using forcefully crashed aircrafts (d2073237-5b52-11e3-80f7-c86000cbc6ec)

medium Nessus Plugin ID 71166

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The OpenTTD Team reports :

The problem is caused by incorrectly handling the fact that the aircraft circling the corner airport will be outside of the bounds of the map. In the 'out of fuel' crash code the height of the tile under the aircraft is determined. In this case that means a tile outside of the allocated map array, which could occasionally trigger invalid reads.

Solution

Update the affected package.

See Also

https://security.openttd.org/en/CVE-2013-6411

http://bugs.openttd.org/task/5820

https://github.com/OpenTTD/OpenTTD

http://www.nessus.org/u?4248e98f

Plugin Details

Severity: Medium

ID: 71166

File Name: freebsd_pkg_d20732375b5211e380f7c86000cbc6ec.nasl

Version: 1.7

Type: local

Published: 12/3/2013

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:openttd, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 11/28/2013

Vulnerability Publication Date: 11/28/2013

Reference Information

CVE: CVE-2013-6411