Candidate: CVE-2010-4168 PublicDate: 2010-11-17 16:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4168 Description: Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daemon crash) by abruptly disconnecting during transmission of the map from the server, related to network/network_server.cpp; (2) remote attackers to cause a denial of service (invalid read and daemon crash) by abruptly disconnecting, related to network/network_server.cpp; and (3) remote servers to cause a denial of service (invalid read and application crash) by forcing a disconnection during the join process, related to network/network.cpp. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_openttd: upstream_openttd: released (1.0.5) dapper_openttd: DNE hardy_openttd: not-affected karmic_openttd: not-affected lucid_openttd: ignored (reached end-of-life) maverick_openttd: ignored (reached end-of-life) natty_openttd: ignored (reached end-of-life) oneiric_openttd: ignored (reached end-of-life) precise_openttd: not-affected (1.1.4-1) quantal_openttd: not-affected (1.2.0-1) raring_openttd: not-affected (1.2.0-1) saucy_openttd: not-affected (1.2.0-1) devel_openttd: not-affected (1.2.0-1)