VDB
CVE-2010-4168
CVE-2010-4168
PUBLISHED
CVSS 5 MEDIUM
Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daemon crash) by abruptly disconnecting during transmission of the map from the server, related to network/network_server.cpp; (2) remote attackers to cause a denial of service (invalid read and daemon crash) by abruptly disconnecting, related to network/network_server.cpp; and (3) remote servers to cause a denial of service (invalid read and application crash) by forcing a disconnection during the join process, related to network/network.cpp.
EPSS 2.84% · 86.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.84%
86.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fedoraproject | fedora | 13, 14 |
| openttd | openttd | 1.0.0 |
| n/a | n/a | n/a |
Timeline
- Nov 17, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://vcs.openttd.org/svn/changeset/21182 url
- http://www.securityfocus.com/bid/44844 url
- 42578 third-party-advisory
- ADV-2010-2985 vdb
- http://security.openttd.org/en/CVE-2010-4168 url
- FEDORA-2010-18572 vendor-advisory
- [oss-security] 20101115 Re: CVE request for OpenTTD mailing-list
- http://security.openttd.org/en/patch/28.patch url
- FEDORA-2010-18571 vendor-advisory
- [oss-security] 20101114 CVE request for OpenTTD mailing-list
- ADV-2010-3199 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-4168 advisory