VDB
CVE-2009-4007
CVE-2009-4007
PUBLISHED
CVSS 5 MEDIUM
Unspecified vulnerability in the NormaliseTrainConsist function in src/train_cmd.cpp in OpenTTD before 0.7.5-RC1 allows remote attackers to cause a denial of service (daemon crash) via certain game actions involving a wagon and a dual-headed engine.
EPSS 1.66% · 82.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.66%
82.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openttd | openttd | 0.5.1, 0.1.1, 0.1.2 |
| n/a | n/a | n/a |
Timeline
- Dec 28, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://vcs.openttd.org/svn/changeset/18462/trunk/src/train_cmd.cpp url
- 37487 vdb
- http://binaries.openttd.org/releases/0.7.5/changelog.txt url
- 61356 vdb
- http://www.openttd.org/en/news/112 url
- [oss-security] 20091224 OpenTTD remote DoS mailing-list
- 37929 third-party-advisory
- 37984 third-party-advisory
- ADV-2009-3645 vdb
- FEDORA-2010-0135 vendor-advisory
- FEDORA-2010-0144 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-4007 advisory