Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted CMD_INSERT_ORDER command.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066128.html | vendor advisory |
http://secunia.com/advisories/46075 | third party advisory |
http://bugs.openttd.org/task/4745 | patch |
http://security.openttd.org/en/CVE-2011-3341 | |
http://www.debian.org/security/2012/dsa-2386 | vendor advisory |
http://openwall.com/lists/oss-security/2011/09/02/4 | mailing list patch |
http://bugs.openttd.org/task/4745/getfile/7707/fixcmds.diff | patch |
http://www.securityfocus.com/bid/49439 | vdb entry |
http://openwall.com/lists/oss-security/2011/09/06/2 | mailing list patch |