Two denial of service vulnerabilities have been discovered in the server component of OpenTTD, a free reimplementation of Transport Tycoon Deluxe. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2524-1
Several vulnerabilities have been discovered in openttd, a transport business simulation game. Multiple buffer overflows and off-by-one errors allow remote attackers to cause denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2386-1
The OpenTTD server is vulnerable to a remote Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200609-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: OpenTTD: Remote Denial of Service Date: September 06, 2006 Bugs: #131010 ID: 200609-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The OpenTTD server is vulnerable to a remote Denial of Service. Background ========= OpenTTD is a clone of Transport Tycoon Deluxe. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 games-simulation/openttd < 0.4.8 > = 0.4.8 Description ========== OpenTTD is vulnerable to a Denial of Service attack due to a flaw in the manner the game server handles errors in command packets. Impact ===== An authenticated attacker can cause a Denial of Service by sending an invalid error number to a vulnerable OpenTTD server. Workaround ========= There is no known workaround at this time. Resolution ========= All OpenTTD users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-simulation/openttd-0.4.8" References ========= [ 1 ] CVE-2006-1998 https://www.cve.org/CVERecord?id=CVE-2006-1998 [ 2 ] CVE-2006-1999 https://www.cve.org/CVERecord?id=CVE-2006-1999 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200609-03 Concerns? ======== Security is a primary focus of Gentoo Linuxand ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.