Candidate: CVE-2012-3436 PublicDate: 2012-10-09 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3436 http://security.openttd.org/en/CVE-2012-3436 Description: OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to "the water/coast aspect of tiles which also have railtracks on one half." Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683258 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_openttd: upstream: http://security.openttd.org/en/CVE-2012-3436 upstream_openttd: released (1.2.2) hardy_openttd: ignored (reached end-of-life) lucid_openttd: ignored (reached end-of-life) natty_openttd: ignored (reached end-of-life) oneiric_openttd: ignored (reached end-of-life) precise_openttd: ignored (reached end-of-life) precise/esm_openttd: DNE (precise was needed) quantal_openttd: ignored (reached end-of-life) raring_openttd: not-affected (1.2.3-1) saucy_openttd: not-affected (1.2.3-1) trusty_openttd: not-affected (1.2.3-1) trusty/esm_openttd: DNE (trusty was not-affected [1.2.3-1]) utopic_openttd: not-affected (1.2.3-1) vivid_openttd: not-affected (1.2.3-1) vivid/stable-phone-overlay_openttd: DNE vivid/ubuntu-core_openttd: DNE wily_openttd: not-affected (1.2.3-1) xenial_openttd: not-affected (1.2.3-1) yakkety_openttd: not-affected (1.2.3-1) zesty_openttd: not-affected (1.2.3-1) devel_openttd: not-affected (1.2.3-1)