https://bugzilla.novell.com/show_bug.cgi?id=414612
User krahmer@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=414612#c493714
Summary: VUL-0: openttd remote buffer overflow
Product: openSUSE 11.0
Version: Final
Platform: Other
OS/Version: openSUSE 11.0
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Development
AssignedTo: kssingvo@novell.com
ReportedBy: krahmer@novell.com
QAContact: qa@suse.de
CC: security-team@suse.de
Found By: ---
Date: Mon, 4 Aug 2008 20:53:14 +0200
From: Nico Golde
To: oss-security@lists.openwall.com
Mail-Followup-To: oss-security@lists.openwall.com
X-Mailer: netcat 1.10
X-GPG: 0x73647cff
Subject: [oss-security] CVE id request: openttd
[-- PGP output follows (current time: Tue 05 Aug 2008 08:31:05 AM CEST) --]
gpg: Signature made Mon 04 Aug 2008 08:53:13 PM CEST using DSA key ID 73647CFF
gpg: Can't check signature: public key not found
[-- End of PGP output --]
[-- The following data is signed --]
Hi,
Can I get a CVE id for the following security issues fixed
in openttd 6.2?
"OpenTTD servers of version 0.6.1 and below are susceptible to a remotely
exploitable buffer overflow when the server is filled with companies and
clients with names that are (near) the maximum allowed length for names.
In the worst case OpenTTD will write the following (mostly remotely
changable bytes) into 1460 bytes of malloc-ed memory:
up to 11 times (amount of players) 118 bytes
up to 8 times (amount of companies) 124 bytes
and 7 "header" bytes
Resulting in up to 2297 bytes being written in 1460 bytes of malloc-ed
memory. This makes it possible to remotely crash the game or change the
gamestate into an unrecoverable state. "
This is Debian bug #493714.
I didn't yet have the time to check the diff between the versions.
Kind regards
Nico
--
Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.