CVE-2010-4168: Use After Free
Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daemon crash) by abruptly disconnecting during transmission of the map from the server, related to network/networkserver.cpp; (2) remote attackers to cause a denial of service (invalid read and daemon crash) by abruptly disconnecting, related to network/networkserver.cpp; and (3) remote servers to cause a denial of service (invalid read and application crash) by forcing a disconnection during the join process, related to network/network.cpp.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4168?
CVE-2010-4168 has a medium severity rating as it can lead to denial of service.
How do I fix CVE-2010-4168?
To fix CVE-2010-4168, upgrade OpenTTD to version 1.0.5 or later.
Which versions are affected by CVE-2010-4168?
CVE-2010-4168 affects OpenTTD versions from 1.0.0 to 1.0.4.
What kind of attacks could be executed using CVE-2010-4168?
Attackers could exploit CVE-2010-4168 to cause a crash of the server's daemon through abrupt disconnections.
Is there a patch available for CVE-2010-4168?
Yes, there are patches available to address CVE-2010-4168, but upgrading is recommended.