CVE-2010-2534: Medium severity openr opentmpfiles vulnerability
The NetworkSyncCommandQueue function in network/networkcommand.cpp in OpenTTD before 1.0.3 does not properly clear a pointer in a linked list, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted request, related to the client command queue.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2534?
CVE-2010-2534 is classified as a denial of service vulnerability due to its potential to cause infinite loops and excessive CPU consumption.
How do I fix CVE-2010-2534?
To fix CVE-2010-2534, upgrade OpenTTD to version 1.0.3 or later, which addresses this vulnerability.
Which versions of OpenTTD are affected by CVE-2010-2534?
CVE-2010-2534 affects OpenTTD versions prior to 1.0.3, including all versions from 0.1.1 up to and including 1.0.2.
What type of attack can exploit CVE-2010-2534?
An attacker can exploit CVE-2010-2534 through crafted requests sent to the server, leading to a denial of service.
Is CVE-2010-2534 a remotely exploitable vulnerability?
Yes, CVE-2010-2534 is remotely exploitable, allowing attackers to affect the server without direct access.