CVE-2012-3436: Input Validation
OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to "the water/coast aspect of tiles which also have railtracks on one half."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3436?
CVE-2012-3436 has a severity that can lead to denial of service due to a NULL pointer dereference.
How do I fix CVE-2012-3436?
To fix CVE-2012-3436, update to OpenTTD version 1.2.2 or later where the vulnerability has been addressed.
Which versions of OpenTTD are affected by CVE-2012-3436?
Versions 0.6.0 through 1.2.1 of OpenTTD are affected by CVE-2012-3436.
Can CVE-2012-3436 be exploited remotely?
Yes, CVE-2012-3436 can be exploited remotely by attackers to crash the OpenTTD server.
What kind of impact does CVE-2012-3436 have?
The impact of CVE-2012-3436 is primarily a server crash leading to service interruption.