VDB
CVE-2010-4168
CVE-2010-4168
PUBLISHED
CVSS 7.5 HIGH
Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daemon crash) by abruptly disconnecting during transmission of the map from the server, related to network/network_server.cpp; (2) remote attackers to cause a denial of service (invalid read and daemon crash) by abruptly disconnecting, related to network/network_server.cpp; and (3) remote servers to cause a denial of service (invalid read and application crash) by forcing a disconnection during the join process, related to network/network.cpp.
EPSS 3.67% · 89.3th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
3.67%
89.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fedoraproject | fedora | 13, 14 |
| openttd | openttd | 1.0.0 |
| n/a | n/a | n/a |
Timeline
- Nov 17, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- http://www.securityfocus.com/bid/44844 url
- http://security.openttd.org/en/CVE-2010-4168 url
- [oss-security] 20101114 CVE request for OpenTTD mailing-list
- ADV-2010-3199 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-4168 advisory
- http://secunia.com/advisories/42578 url
- http://www.vupen.com/english/advisories/2010/2985 url
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052193.html mailing_list
- http://security.openttd.org/en/patch/28.patch patch
- http://vcs.openttd.org/svn/changeset/21182 technical
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052187.html mailing_list
- http://marc.info/?l=oss-security&m=128984298802678&w=2 mailing_list